Known CVEs
0
Highest CVSS
In KEV
0
Vendor
lnv7210r firmware
Connections
97 relationships
216 milioni di Smart TV possono spiarti: il problema è dentro casa
Il noto portale tecnologico Gamers Nexus , in collaborazione con gli esperti di Level1Techs , hanno condotto un’ampia indagine sui televisori LG che utilizzano webOS . Durante l’indagine, gli specialisti hanno scoperto che i dispositivi scansionano la rete domestica del proprietario, raccolgono informazioni sulle reti Wi-Fi vicine e sul contenuto visualizzato . Inoltre, i ricercatori hanno rilevato che le richieste vocali riconosciute vengono salvate nei log di webOS in chiaro . Dopo aver compromesso il televisore, gli specialisti sono riusciti a utilizzarlo per registrare l’audio anche con lo schermo spento. Durante l’indagine, ora pubblicata su YouTube della durata di oltre due ore, gli esperti hanno analizzato il traffico di rete e i firmware di diverse modelli di televisori OLED LG, inclusa la serie G5. Alla fine, i ricercatori hanno scoperto che i televisori sono in grado di determinare gli indirizzi IP e la posizione dei loro proprietari, raccolgono informazioni sulle reti Wi-Fi disponibili nelle vicinanze (SSID, livello del segnale e canali utilizzati), e scansionano la rete locale, rilevando i dispositivi ad essa collegati e i loro indirizzi IP interni. Secondo Steve Burke, capo redattore di Gamers Nexus, il televisore G5 testato ha rilevato decine di dispositivi non correlati, tra cui smartphone e smartwatch dei dipendenti. È stato sottolineato che per eseguire tale scansione non era necessario un hack o lo sfruttamento di vulnerabilità, quindi si tratta di funzionalità standard del dispositivo. I rappresentanti di LG hanno dichiarato al portale Ars Technica che la ricerca di dispositivi compatibili nella stessa rete è necessaria per il collegamento di vari gadget, la condivisione di contenuti e il funzionamento delle funzioni smart home. L’azienda ha sottolineato che la scansione della rete locale è una funzionalità standard di qualsiasi TV e dispositivo IoT moderno. Un’altra parte dell’indagine di Gamers Nexus è dedicata alla tecnologia Automatic Content Recognition (ACR) , utilizzata dai televisori LG. Questa tecnologia consente di creare impronte digitali di audio e video, e poi di determinare quale contenuto sta guardando l’utente. Tale analisi può riguardare non solo le app integrate del TV, ma anche i contenuti provenienti da dispositivi collegati al televisore tramite HDMI e altre porte (come monitor, computer, decoder TV, ecc.). In precedenza, gli esperti di sicurezza informatica avevano già svolto analisi sull’uso diffuso dell’ACR da parte dei produttori di televisori, ponendo domande sulla sicurezza e la privacy. Gli specialisti avevano anche sottolineato che rifiutare tale monitoraggio può essere piuttosto difficile e spesso richiede un approfondito studio delle varie impostazioni del TV in numerose sottosezioni, senza che esista un interruttore universale per disattivarlo. Come ora osservano i ricercatori di Gamers Nexus, LG utilizza inoltre i dati ottenuti tramite ACR nel proprio business pubblicitario. Ad esempio, la divisione LG Ad Solutions afferma che solo negli Stati Uniti la piattaforma copre 49 milioni di televisori LG basati su webOS, nonché fino a 363 milioni di altri dispositivi collegati agli stessi nuclei familiari (come smartphone e computer). Questo permette ai pubblicitari di mostrare pubblicità mirata agli utenti su più dispositivi. Tuttavia, ancora più domande sono state sollevate dai ricercatori riguardo le funzioni vocali dei televisori LG. Infatti, in webOS sono state trovate richieste vocali riconoscibili e non anonimizzate, che venivano salvate nei log di sistema in chiaro. Per dimostrare ciò, gli specialisti hanno attivato le ricerce vocali e poi pronunciato vicino al televisore una frase di prova con un numero di previdenza sociale. Successivamente, questa frase è stata trovata nei log quasi nella stessa forma in cui era stata pronunciata. Tuttavia, i ricercatori non sono riusciti a dimostrare che tali trascrizioni vengono inviate ai server di LG: sebbene il dispositivo si sia collegato ai server dell’azienda, il traffico di rete era crittografato e il contenuto dei pacchetti inviati non è stato possibile analizzare.  Separatamente, i ricercatori di Gamers Nexus hanno dimostrato che, in caso di compromissione di webOS, il televisore può essere utilizzato per registrare l’audio in modo nascosto. Ottenendo l’accesso completo al sistema, gli specialisti sono riusciti a utilizzare queste funzioni anche quando il televisore era in modalità standby e il suo schermo era spento. La registrazione era possibile anche senza connessione a Internet: i dati venivano salvati localmente sul dispositivo. I rappresentanti di LG contestano queste affermazioni dei ricercatori. In particolare, l’azienda ha riportato ad Ars Tecnica che in modalità standby i televisori “ascoltano” gli utenti solo per riconoscere la frase chiave e solo nel caso in cui l’utente abbia precedentemente attivato la funzione Far-Field Voice Recognition. Se la frase chiave non viene rilevata, il suono viene elaborato localmente, viene eliminato immediatamente e non viene inviato ai server di LG. Inoltre, secondo i rappresentanti dell’azienda, i televisori non raccolgono, registrano o trasmettono all’esterno le conversazioni, a meno che l’utente non attivi intenzionalmente le funzioni vocali. Va notato che alcuni modelli di televisori LG (inclusa la serie G5 testata) sono dotati di un interruttore fisico per il microfono integrato . Gli esperti hanno confermato che funziona effettivamente e, quando disattivato, il microfono del televisore smette di ricevere suoni. Tuttavia, dopo la compromissione di webOS, gli specialisti sono riusciti a utilizzare altre fonti audio disponibili per il televisore. Ad esempio, sono riusciti a registrare una conversazione tramite una webcam USB collegata e il microfono del telecomando, anche se il microfono integrato del TV era fisicamente disattivato. Separatamente, nel loro video, il team di Gamers Nexus ha riferito che durante l’indagine ha scoperto in webOS diverse vulnerabilità, inclusa la possibilità di esecuzione remota di codice . I dettagli su questi bug non sono ancora stati resi pubblici, poiché i ricercatori seguono la politica di divulgazione responsabile delle informazioni. L'articolo 216 milioni di Smart TV possono spiarti: il problema è dentro casa proviene da Red Hot Cyber .
redhotcyber.comSep 11, 2026extracted
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already there. Nothing here needed magic. Mostly access, trust, weak edges, and someone willing to keep poking. That’s the week. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Malicious extensions steal crypto dataA set of four malicious Google Chrome and Mozilla Firefox extensions has been found to target Axiom Trade and Padre users to steal session tokens and wallet data. The extensions are J7Tracker (Chrome), VREO (Chrome and Firefox), and Orbit Tracker (Firefox). While the first three contain the same Axiom and Padre collection module, the fourth implements a different collector but targets the same data, while retaining some artifacts from J7Tracker. "The module is byte-identical across all three analyzed extensions. It automatically retrieves authenticated user information, wallet-related bundle data, Firebase access tokens, and application state, then sends the information to threat actor-controlled Vercel deployments," Socket said. The same Chrome publisher has been traced back to two earlier extensions, GhostApe and GhostApe Color, impersonating the MockApe trading add-on. AI agents automate cyber intrusionsA Chinese-speaking operator has been observed using Anthropic Claude Code, Alibaba Qwen, and DeepSeek to automate intrusions against government and financial systems in Afghanistan, Thailand, Taiwan, and the U.S. Some of the targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The attacker is said to have used SecFlow, an AI orchestration framework, to convert "campaign objectives into tasks for specialized AI agents" and supply them with tools, target information, shared storage, and network routes, Hunt.io said, adding the tool "split reconnaissance, exploitation, collection, and reporting among specialist workers." Some of the vulnerabilities exploited by the threat actor are Shellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass. The exploitation is followed by the deployment of web shells, which are generated through a dedicated GLUTTON capability, and used to facilitate follow-on actions, like reconnaissance, privilege escalation, credential theft, and custom implant deployment. One such backdoor is SecBox, a Go-based remote-access and network-pivot framework. Details of the campaign first came to light in July 2026. Shadow AI exposes sensitive dataThe U.K.'s National Cyber Security Center (NCSC) has warned that employees using unapproved AI tools can expose sensitive corporate data and create security risks that organizations may struggle to detect and manage. "Providing shadow AI access to company or customer data likely increases the risk of data breaches, intellectual property loss and failure to meet regulatory requirements," NCSC said. "Employees who transfer sensitive or proprietary information to consumer AI services will likely reduce the organization's visibility and control over that information. AI agents are complex pieces of software that can have critical security vulnerabilities. If an attacker successfully exploits a vulnerability, they can gain access to the same data, services, and privileges that the agent has legitimate access to." Fake M&A deals drive wire fraudAttackers are masquerading as executives and tricking targets in legal teams into moving conversations to WhatsApp and personal email with an aim to initiate international wire transfers using forged acquisition documents as part of a merger and acquisition scam. "The attackers presented the acquisition as a tightly controlled transaction coordinated by a reputable adviser, with only a small group involved and an announcement approaching fast," Gen Digital said. "The organizations and professions varied. The targets included senior people in private equity, industrial finance, sales, mining and energy. For each of them, an acquisition or strategic investment narrative would have been credible enough to justify initial engagement. Despite the different branding, the documents followed substantially the same sequence of sections and reused the same legal language. They all imposed confidentiality, directed communications towards WhatsApp and personal email, and introduced a short period between the NDA date and the supposed public announcement." Windows adds privacy-preserving age checksMicrosoft is adding new age-awareness APIs called the Windows Age API to Windows 11 that will allow apps to determine whether a user is a child, teenager, or adult without exposing their exact date of birth. "Apps receive only the age-related signal needed for the experience and not sensitive personal data such as full date of birth," Microsoft said. "By making age awareness available as a platform capability, Windows helps developers build safeguards into experiences from the start rather than placing the burden on children and families to manage protections app by app." 119K domains power fake shopsA massive operation dubbed DoppelCart is using more than 119,000 domains to run a network of fake e-commerce shops that steal payment card details. The sites mimic legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes even loading assets directly from the real company's servers. In all, the shops mimic 44,182 different brands, with a median of two clones for each. "Each copies a real brand's photos and page text, then undercuts its prices," Netby said. "Each also republishes the brand's own support address, so the people who get charged complain to the brand, not the shop." Chrome accelerates security releasesGoogle has officially shifted to a two-week cadence for major Chrome milestones, with weekly security updates, in response to a shifting cybersecurity landscape in the AI era. The shift is driven by LLM-assisted vulnerability discovery approaches, which have increased the volume of patches and updates across the software ecosystem. "While this dramatic change in software security brought about by LLMs might be startling, an increase in bugs found and fixed is not a sign of failure," Google said. "Every bug found and fixed is one less foothold for an attacker. But discovering and fixing a bug is only half the battle — we must also ship the fix and apply the update for users faster than adversaries can exploit the bug." The idea, therefore, is to shrink the window between pushing a fix in a public codebase and getting that fix to end users before it can be exploited. A shorter release cycle would reduce the patch gap – the time frame between when a security vulnerability is known and when it gets addressed. Google moved to a four-week release cycle for Chrome in 2021, down from six weeks. Similar moves have been adopted by other browser makers like Microsoft, Mozilla, and Brave. 200 Android flaws patchedGoogle has released patches for 200 vulnerabilities as part of the September 2026 Android security updates. This includes a number of critical and high-severity vulnerabilities, including those that could allow attackers to remotely execute code without user interaction. One of the flaws worth highlighting is CVE-2026-28662, a critical Wi-Fi-related bug that could potentially allow an attacker to achieve remote code execution. "Most concerning from this list is CVE-2026-28662 because it's a Wi-Fi-related memory corruption flaw," Adam Boynton, enterprise strategy manager at Jamf, said. "If left unpatched, it could enable attackers to execute code remotely, without any additional privileges or user interaction, potentially allowing privilege escalation. This vulnerability will only continue to pose a risk if devices are left unpatched. It's crucial that organizations issue the updates across their device fleet as soon as possible." Singpass scheme tied to 170 victimsSingapore police officials have arrested two male Chinese Malaysians, aged 25 and 47, for their alleged involvement in a coordinated scheme that compromised the Singpass accounts of Singapore citizens and work permit holders. "Investigations revealed that the two men were employees of a mobile phone shop located in Singapore," authorities said. "They allegedly exploited opportunities arising from their work to access customers' Singpass accounts. In one such occasion, when a customer was purchasing a new SIM card, one of the men allegedly offered to help update the mobile number linked to the customer's Singpass account, before using this opportunity to create a LiquidPay account without the customer's knowledge." Investigations have uncovered over 170 Singapore citizens and foreign workers whose Singpass accounts were linked to the same activity. The fraudulent Singpass accounts were then used to register for more than 160 additional LiquidPay accounts. Email breach fuels wallet phishingCryptocurrency hardware wallet maker Trezor has warned customers to be on the lookout for phishing attacks after its third-party email provider Brevo was breached. The incident impacted 120 Brevo accounts, including Trezor's. "Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt," it said. Do not click on any link. The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future." The Brevo account has been suspended to prevent the threat actors from abusing it to send phishing emails. The phishing email sent from the account contained a malicious link that instructed users to download an app that asked them to enter their wallet backup. The domain has since been taken down. 33K+ Plex servers remain exposedData from the Shadowserver Foundation shows that there are over 33,800 exposed Plex servers susceptible to recently disclosed vulnerabilities, down from a high of 37,467 on September 5, 2026. Nearly 20,000 instances are located in North America. EtherRAT chain ends in ransomwareAn attack campaign that installs EtherRAT via a malicious MSI installer masquerading as a Sysinternals tool has been found to deliver an AI-generated malware framework called TukTuk and GoTo Resolve. Using the access provided by the remote access software, the threat actor is said to have successfully exfiltrated data to a cloud service and deployed The Gentlemen ransomware. "TukTuk can use Arweave as a dead-drop resolver," the DFIR Report said. "In this mode, the implant queries the Arweave blockchain for a specific Drive-Id, then retrieves an encrypted configuration blob. That blob contains the credential pool for all supported C2 transports. After execution of TukTuk, the threat actor began hands-on-keyboard activity, Kerberoasting operations, and credential discovery targeting administrative accounts. Next, the threat actor leveraged compromised service account credentials to deploy GoTo Resolve remote management tooling laterally across multiple systems, including servers and domain controllers." CISA refreshes insider threat guidanceThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an updated version of its Insider Threat Mitigation Guide to highlight the "growing impact insider threats have on critical infrastructure, the dynamic and evolving operational landscape, and provide new use cases to help organizations address new challenges." Some of the key updates relate to emerging workplace trends such as increased hybrid and remote work, the use of AI for manipulation and deception, access control, and visitor screening. AI abuse leads to 15-year sentenceJames Strahler II, 37, of Columbus, has been sentenced in the U.S. to 15 years in prison for using both real and AI-generated sexually explicit images and intimidating victims with threats of violence. "Strahler had installed more than 24 AI platforms and more than 100 AI web-based models on his phone," the Justice Department said. "The defendant used telephone calls, voicemails, text messages and web postings to engage in a campaign of harassment against his victims. From December 2024 until June 2025, Strahler sent harassing messages to at least six adult female victims. These messages included nude images of the victims, both real and AI-generated. Strahler also posted online AI-generated obscenities he created of children." The defendant is said to have created more than 700 images of both real victims and animated persons and posted them to a website dedicated to child sexual abuse. He was arrested in June 2025. Bank takeover suspect extraditedSergei Anatolyevich Filimonov, 36, a Russian national and web developer, has been extradited to the U.S. in connection with a transnational cyber-fraud conspiracy responsible for large-scale bank account takeover attacks. "Filimonov and his co-conspirators executed a sophisticated scheme involving spoofed domains that mimicked the websites of federally insured financial institutions," the Justice Department said. "The conspirators purchased sponsored search-engine links to divert unsuspecting banking customers to fraudulent login pages, where victims entered their credentials. The conspirators used the stolen credentials to access bank accounts, review account balances, and initiate unauthorized wire transfers to steal bank account funds." Filimonov is also accused of developing and maintaining online infrastructure supporting the operation, including interactive databases storing more than 5,000 stolen login credentials and software designed to harvest and transmit sensitive authentication data. One of the backend domains linked to the scheme was seized by U.S. authorities in December 2025. Filimonov has pleaded not guilty to the charges. $245M crypto theft ringleader pleads guiltyMalone Lam (aka Anne Hathaway, $$$, and King Greavy), 22, a citizen of Singapore and recent resident of Miami, has pleaded guilty in the U.S. for their role as a "ringleader of an international cybercrime conspiracy" that used social engineering to steal and launder cryptocurrency valued at more than $245 million. "The criminal enterprise began no later than October 2023 and continued through at least May 2025," the Justice Department said. "The scheme developed through connections made on online gaming platforms and was comprised of individuals based in California, Connecticut, New York, Florida, and abroad. The RICO conspiracy used social engineering and occasional home break-ins to obtain information that allowed the conspirators to drain their victims' cryptocurrency wallets." Lam is accused of organizing the enterprise, identifying target victims, and coordinating with different co-conspirators. The stolen assets were used to purchase nightclub services, luxury handbags, high-end watches and clothing, rental homes, private jet rentals, a team of private security guards, and a fleet of exotic cars. Teams to obscure external QR codesMicrosoft said it will provide additional protection for QR codes shared by external users in team messages. "Images containing QR codes from external senders will be obscured by default and require users to reveal them before viewing or scanning," the company said. "This helps reduce the risk of phishing and fraud by encouraging more deliberate interaction with QR code content." The feature is expected to start rolling out next month. Google services abused as phishing relayA newly discovered phishing campaign has been observed routing "victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools," according to KnowBe4 Threat Lab. What's unusual about the attack is that it abuses six distinct Google properties (Meet, Search, DoubleClick, Programmable Search Engine, Image Search, and Tag Manager) across a multi-hop redirection path to bypass email security filters. "The page pulls live company logos from Clearbit, real-time website screenshots from a third-party screenshot API, and uses Google's public DNS to validate the victim's corporate email domain," it added. Recent phishing campaigns have also increasingly exploited .vu, Vanuatu's country-code top-level domain, for setting up malicious infrastructure. KnowBe4 said it recorded a 159% increase in phishing sites, 1,660 unique domains, and over 28,000 malicious emails from April through July 2026. "Security vendors have historically seen almost no .vu traffic, so there is no TLD-level risk signal built into most threat feeds," the company said. Another "iCloud Sign-In Alert" phishing attack has been found to detect the operating system and serve a remote access tool for Windows users and a credential harvesting page for Apple users. "Everyone else gets walked through a fake Microsoft login while a human operator watches the credentials arrive in Telegram in real time," KnowBe4 said. Smart TV privacy claims spark scrutinyLG is drawing criticism over claims from YouTube channel Gamers Nexus that its smart TVs gather extensive information about users and their surroundings to fuel its advertising business. The channel crew said it observed the TV capturing IP addresses, location data, and the names, signal strengths, and channel numbers of nearby Wi-Fi networks. The consumer hardware also enumerated devices on the local network that were not paired with it, including smartphones, watches, routers, thermostats, air purifiers, server baseboard management controllers, and PCs. The move has been described as "an egregious invasion of privacy." In a statement shared with The Register, the company said the allegations are not true. "LG TVs process voice data only when the voice button on the remote control is pressed and held, or when a wake word such as 'Hi LG' is recognized after the user has activated the Far-Field voice recognition feature," the company said. Other than these instances, the TVs do not collect or record ambient conversations. If the wake word is not recognized, no voice data is transmitted to the server; wake word detection is processed locally on the device and immediately deleted. Additionally, to provide smart TV functionalities, LG TVs feature the ability to scan for and connect to nearby devices on the same network. This is a standard function commonly available on smart TVs and smart home devices." Malicious npm packages compromise walletsA set of 13 malicious wallet packages have been discovered on the npm registry. According to InstallSafe, their names reference wallets, signing, analytics, Solana, Base, or mobile components. "Any computer that has this package installed or running should be considered fully compromised," GitHub warns in an advisory. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it. Blob URLs hide phishing pagesBarracuda has disclosed details of a DocuSign-themed attack campaign that replaces the traditional phishing site with a phishing page generated inside the victim’s browser using blob URLs. "Victims are routed through legitimate Microsoft services, making the attack appear trustworthy and reducing common warning signs," the cybersecurity company said. "Because the page exists only within that browser session, there is no persistent phishing URL for security tools to retrieve, analyze, or blocklist in advance. Because the visible navigation remains within trusted Microsoft services, users and automated scanners may be less likely to identify the activity as malicious." 5,400 hacked sites fuel EtherHidingMore than 5,400 compromised websites have been used for carrying out EtherHiding attacks. "The compromised websites have little in common beyond being small businesses (clinics, plumbers, e-commerce shops) with no shared industry, region, or owner," Netskope said. "These compromised sites include either an inline script or a spoofed package that calls the BSC testnet and downloads a ClickFix overlay as the next step of the attack, which instructs visitors to run a command on their PC." Another variant of the attack has been found to open a covert WebRTC data channel for command-and-control (C2) instead of serving the ClickFix overlay and use it to receive and execute arbitrary JavaScript code. Executive SSNs flood dark web marketsRapid7 said it has identified 476 instances of compromised Social Security numbers (SSNs) across 395 unique corporate personnel since early 2026. "Over 73% of these exposures directly targeted top-level leadership, with C-suite executives comprising 44.6% of affected profiles and Presidents making up another 28.6%," it said. "Unsurprisingly, given the geographical nature of SSNs, 95.6% of these leaks stemmed from U.S.-headquartered organizations, concentrated heavily in high-value sectors like Financials (over 25%) and Industrials (17%)." Marketplaces like Xilo, Bankom, and PeopleFinder together account for 81.5% of all executive SSN leaks present in its dataset, led by Xilo at 40.8%, Bankom at 21.8%, and PeopleFinder at 18.9%. MCP tools expose high-impact attack pathsAn analysis of 33,563 published MCP server builds containing 475,865 tools has found that 2 in 5 server builds include a tool that can access sensitive data or take consequential action and 1 in 13 server builds contain a code or command-execution primitive. "When an MCP host makes a tool available to a model, the tool’s description can enter the model's context," Island said. "After the tool is called, its returned text can enter that context too. The model may interpret either as guidance, not just documentation. An attacker may not need a malicious binary. A paragraph of natural language can be enough." This makes the "instruction supply chain" a critical attack surface, allowing bad actors to embed covert instructions in tool descriptions and prompts that a model may read and trigger unintended actions without requiring malicious executable code. "Security teams need a control plane that governs a tool from discovery to execution: inspect its code and instructions, constrain its capabilities, verify configuration changes, and evaluate each action in runtime context," Island said. "Approval cannot be a one-time package score; it must account for the tool version, the agent and user invoking it, the destination, the data in scope, and the action being attempted." MFA-bypassing PhaaS hits 40+ countriesHundreds of organizations across more than 40 countries have been targeted by BigBear 2.0, a rebranded Evilginx2-based Microsoft 365 phishing-as-a-service (PhaaS) operation. The stolen records are tied to 461 organizations. CloudSEK, which was able to gain admin access to the threat actor panel, said the operation has "exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies — affecting 3,331 unique victim IPs across 40+ countries." The multi-user PhaaS panel has been leased to at least five affiliate operators so far. "The core technique employed is adversary-in-the-middle (AitM) phishing," CloudSEK said. "Unlike classical phishing that only captures passwords, Evilginx2's reverse proxy relays the entire session." FBI unveils first cyber strategyThe U.S. Federal Bureau of Investigation (FBI) has outlined its first-ever cyber strategy, stating it "will detect shifts in adversary intent and capability, disrupt their ability to profit or operate safely, expose their tradecraft and enablers, bring offenders to justice with domestic and international partners, and provide the evidence and intelligence that underpin sanctions, diplomatic action, and partner law enforcement actions." The agency also aims to attribute malicious cyber activity with confidence, support victims following intrusions, share actionable intelligence, and partner with U.S. allies and the private sector to increase impact. Furthermore, the agency said it will "adopt agentic AI in ways that securely scale defense and disruption, and will implement AI-enabled tools to detect, divert, and deceive threat actors where operationally appropriate." The lesson this week is smaller than “patch faster.” Stop giving ordinary things unlimited trust. Extensions, packages, redirects, sessions, AI tools, exposed services — most of the trouble begins when something familiar is allowed to do too much. Security still breaks at the boring handoffs: what gets access, what stays exposed, what gets inherited, and what nobody checks twice. Attackers do not need every door open. One lazy hinge is enough. That is probably the part worth remembering after the headlines disappear.
thehackernews.comSep 10, 2026extracted
LG accused of 'egregious invasion of privacy' over TV data collection
LG is once again fending off allegations that its expensive consumer hardware gathers extensive information about users and their surroundings for the benefit of its advertising business. The latest concerns center on smart TVs that researchers claim continued capturing audio after voice recognition was activated, including while the display was in standby. The claims once again come from the folks behind the Gamers Nexus YouTube channel, which also claimed in July that LG's monitors were surreptitiously installing adware using an automatic Windows process. After inspecting the TVs' network traffic and internal data, editor-in-chief Stephen Burke said the team found plaintext transcripts generated from audio captured by the TV, along with other information. The Gamers Nexus crew said it observed the TV collecting IP addresses, location data, and the names, signal strengths, and channel numbers of nearby Wi-Fi networks. The TV also enumerated devices on the local network that were not paired with it, including smartphones, watches, routers, thermostats, air purifiers, server baseboard management controllers, and PCs. Burke added that Wireshark packet capture analysis revealed such a large quantity of private data that it couldn't be displayed in the video, and that this was all native behavior from LG's equipment. He said the findings represented "an egregious invasion of privacy." Burke and company also claimed that the TVs could continue capturing audio while disconnected from the internet, store it locally, and transmit related data after connectivity was restored. Burke said the team was working with security researchers to disclose vulnerabilities responsibly, including an alleged remote code execution flaw. The Register has asked LG for comment. LG previously told other publications that its TVs do not "collect, record, or store ambient conversations," and that voice recognition is an optional feature that processes voice data only when activated by the user. LG's relationship with ads LG does not hide the fact that its hardware incorporates technology from its advertising business, LG Ads Solutions. In 2022, it announced that automatic content recognition (ACR) technology previously limited to its US smart TVs would be deployed in sets sold across 27 countries, with the resulting insights available through its advertising business. LG said the ACR data was anonymized and handled in accordance with privacy regulations. Its advertising customers could use the resulting insights to measure campaign effectiveness and whether an ad led to registrations for an app or service. LG is not alone. Most major smart TV manufacturers deploy some form of ACR in their hardware, although the controls available to users vary by vendor. The source of so much frustration, however, is that manufacturers are not forthcoming with consumers at the point of purchase about the extent to which their data is collected or how. Generating audio transcripts while the display is in standby is not something LG highlights in its product descriptions or marketing materials. According to Gamers Nexus, however, that is what its testing uncovered. Instead, the company's website describes its TVs' voice features using terms such as "Intelligent Voice Recognition" and "Clear Voice Pro." Customers who go digging for more details must navigate to an "LG Privacy" link most of the way down a lengthy product page. From there, they must sift through four links to understand its privacy policies more fully, although neither the documents nor the main product page references LG Ads Solutions. Gamers Nexus claims LG sends all the data its hardware collects to the ads unit, which claims in its marketing materials that customers can "own the living room," having their ads appear on devices inside "the connected LG household." LG Ads Solutions' official fact sheet, which predictably requires you to enter your personal and contact details to access, states that there are 49 million LG TVs in the US powered by its webOS, but the company's total reach extends to 363 million "addressable secondary devices." To potential customers, it promises "precision targeting at the device level, across households." ACR and other data-collection technologies have become commonplace across the smart TV market. Research suggests that many consumers are willing to trade their data for tangible financial savings, but the privacy implications are compounded when you consider these devices can be found mounted in boardrooms and doctors' offices. Twice bitten The allegations come less than two months after Gamers Nexus reported that connecting certain LG monitors to an online Windows 11 PC could trigger installation of the LG Monitor App through Windows' device metadata system. The behavior depended on the user selecting Recommended Settings during Windows setup and being signed into the Microsoft Store. As we reported at the time, the LG Monitor App Installer has limited utility and displayed pop-up promotions for McAfee. LG told us: "LG Electronics reiterates that McAfee is not installed automatically and is never installed without the user's explicit consent." ®
theregister.comSep 8, 2026extracted
LG TV flaws could let attackers listen in, even in standby mode
Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using  Automated Content Recognition (ACR) .  ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits. Now, a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, has examined several LG TV models. The team says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised. Some findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer. According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers. This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use. The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored. The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing. A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices. How to stay safe The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home. There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access: Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings. Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need. Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible. Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network. Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet. Our earlier guide to disabling ACR includes instructions for several popular TV brands. Browse like no one’s watching.   Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal.  Try it free →  
malwarebytes.comSep 7, 2026extracted
Il capo di Nvidia affida al figlio e alla figlia la guida di progetti di robotica
Mentre le autorità statunitensi stanno valutando la possibilità di vietare l’importazione di robot di produzione cinese, l’azienda americana Nvidia collabora attivamente con gli sviluppatori locali, fornendo loro non solo hardware ma anche software. I figli del fondatore di Nvidia partecipano attivamente a questo processo. Lo ha ricordato l’edizione The Wall Street Journal , segnalando separatamente che il business legato all'”IA fisica” frutta a Nvidia circa 10 miliardi di dollari di fatturato annuo. Secondo le parole del CEO e fondatore Jensen Huang, nei prossimi dieci anni il fatturato di Nvidia in questo settore crescerà di dieci volte. Oltre ai chip specializzati come Thor , utilizzati dai principali produttori cinesi di robot antropomorfi come Unitree, l’azienda americana fornisce loro anche software per lo sviluppo di modelli IA applicativi. Questi ultimi sono offerti con pesi aperti, il che semplifica notevolmente l’accesso degli sviluppatori a tale software. Come osserva la fonte, i figli di Huang sono attivamente coinvolti nella promozione dei prodotti e dei servizi dell’azienda di loro padre nel settore della robotica. La figlia Madison dirige il servizio marketing in questo ambito, mentre il figlio Spencer supervisiona lo sviluppo dei prodotti e tiene già conferenze in eventi di settore. Nel mese appena trascorso, Madison Huang non solo ha visitato l’azienda LG Electronics in Corea del Sud, ma ha partecipato anche alla Fiera Mondiale dei Robot a Pechino , dove è stata vista vicino agli stand delle aziende cinesi che utilizzano la piattaforma Nvidia nei loro sviluppi. Attualmente, in Cina viene prodotta circa il 90% di tutti i robot antropomorfi, quindi Nvidia non può permettersi di ignorare le esigenze del mercato locale. Le autorità cinesi mirano all’autosufficienza dell’industria robotica locale, ma in termini di componenti e software di controllo, i produttori di robot cinesi dipendono ancora fortemente da Nvidia. Almeno, tutto ciò è necessario nella fase di sviluppo e addestramento dei robot. Nei laboratori Nvidia in Cina e negli Stati Uniti sono presenti campioni di robot antropomorfi di produzione cinese, utilizzati per condurre esperimenti. Nvidia pubblica lavori scientifici di ricercatori cinesi nel campo della robotica e li coinvolge nella collaborazione. Contemporaneamente, si espande il personale di Nvidia in Cina, che si occupa di robotica e autopilota per i trasporti. A luglio, Jensen Huang ha ammesso che l’autopilot sarà il primo campo di applicazione della robotica che avrà un impatto significativo sul mercato e possiederà un serio potenziale economico. L'articolo Il capo di Nvidia affida al figlio e alla figlia la guida di progetti di robotica proviene da Red Hot Cyber .
redhotcyber.comAug 31, 2026extracted
Zenity Raises $125 Million in Series C Funding
AI security and governance company Zenity has raised $125 million in a Series C funding round that brings its total raised to $180 million. The investment round was led by Norwest, with additional support from Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures, and previous backers Vertex Ventures, Third Point Ventures, DTCP, and Intel Capital. Since its inception in 2021, Tel Aviv-based Zenity has been helping organizations securely adopt AI through understanding agents’ intent and deterministically allowing, modifying, or blocking their actions. The company’s platform can distinguish between legitimate work and manipulated, compromised, or rogue behavior to prevent nefarious agent operations before they can harm an organization. Zenity provides enterprises with a unified security layer covering a broad spectrum of agentic AI frameworks, including Copilot, ChatGPT Enterprise, Gemini, Claude Codex, and Cursor, as well as custom-built systems in Bedrock, AgentCore, Foundry, and Vertex AI. Additionally, through Zenity Labs, the company hunts for vulnerabilities in agentic AI platforms, including zero-click attacks that could silently hijack enterprise AI agents for data exfiltration and system compromise. Zenity has over 230 employees worldwide, operating an R&R center in Tel Aviv and running its go-to-market and operations from New York. The new funding will accelerate product innovation, Zenity Labs’ expansion, and global presence widening. “As enterprises rapidly adopt AI agents across critical workflows, organizations need a new approach to security built for this new and continuously evolving reality,” Norwest partner Assaf Harel said. “Zenity has an early mover advantage in building end-to-end AI agent security and the largest and rapidly growing footprint of successful implementation across Fortune 1000 customers. The company is in pole position to emerge as a category leader,” Harel added. Related: Obsidian Security Raises $85 Million at $1.1 Billion Valuation Related: Horizon3 Raises $250 Million to Fund Continuing Growth Related: DataBahn Raises $40 Million for Agentic Data Pipeline Management
securityweek.comAug 4, 2026extracted
South Korea fines telco giant KT $39 million for customer data breach
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. The penalty was imposed for an internal network compromise that persisted for nearly 11 months, between October 8, 2024 and September 5, 2025. PIPC launched an investigation into a potential data breach on September 10, 2025, following user reports of fraudulent micropayments. A day later, the company filed its initial data breach notification, reporting that data of roughly 5,500 customers had been exposed. The government agency's investigation determined that the incident exposed the personal information of 16,647 KT subscribers and caused fraudulent mobile payments of KRW 240 million ($167,400) for at least 368 of them. KT Corporation is South Korea's largest telecommunications operator, providing mobile and fixed-line communications, broadband internet, IPTV, cloud, data center, and enterprise IT services. The company, which employs 23,300 people, serves over 13.5 million mobile subscribers, 90% of the country’s fixed-line subscribers, and 45% of high-speed internet users. Rogue mobile station The point of breach was a lost KT cellular base station called a femtocell, which contained a valid authentication certificate. The attackers retrieved this certificate and installed it on a self-made device, which then appeared as a legitimate part of KT’s network, capturing cellular traffic from nearby devices connecting to the rogue femtocell. This allowed the hacker to intercept communications between users’ devices and KT’s core network, including mobile phone numbers, IMSI, and IMEI numbers. Eventually, the attackers combined the intercepted data with additional personal information and captured SMS and ARS authentication codes used for mobile micro-payments. PIPC notes that KT installed femtocells itself, fully owned the devices, and controlled network authentication and authorization. The Commission alleges that KT’s security controls were inadequate because femtocell certificates remained valid for 10 years, connections weren’t restricted by source IP addresses, and a route existed that bypassed the femtocell management server. These weaknesses allowed the hackers to remain connected to KT’s network and collect sensitive client data for 11 months, without being detected. BFDoor malware infection During the investigation, PIPC also discovered that 38 KT IT service network servers had been compromised by malware, including BPFDoor, in March 2024. BPFDoor is a stealthy Linux and Solaris backdoor publicly documented in 2022 that evaded detection for more than five years. PwC later linked its use to the China-nexus Red Menshen espionage group that targeted telecommunications providers and organizations in other critical sectors. The malware uses Berkeley Packet Filter (BPF) technology to passively monitor network traffic, allowing attackers to activate the malware with specially crafted "magic" packets without opening listening ports, effectively bypassing firewall protections and enabling covert remote shell access. The Commission alleges that KT knew about the malware infection since March 2024, but failed to report it to the authorities, and handled the incident internally with no transparency towards its customers. Later, the firm even deleted logs from some compromised servers while conducting malware inspection, following a malware breach on another telecom firm, LG U+. LG U+ followed a similar evidence-wiping approach, reinstalling the operating system OS and disposing of servers before the investigators could determine the full impact of the breach. Due to KT wiping those historical network logs, the Commission says it could not determine whether additional customer data had been stolen. As part of the enforcement action, PIPC ordered KT to strengthen security controls for femtocells and other telecommunications equipment, reinforce governance over personal information protection, ensure its Chief Privacy Officer plays a substantive role in oversight, and expand ISMS-P certification to cover its mobile network systems. The Commission also announced plans to pursue legislative changes that would introduce stronger penalties for companies that conceal or destroy evidence before or during investigations. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 30, 2026extracted
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on Monday, the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA) said they pulled more than 200 servers offline. Investigators estimate roughly 1,800 paying customers used Kratos to run about 15,000 phishing campaigns a month. Kratos harvested more than passwords. The kit was designed to steal the session cookie along with the login, and that cookie is enough to walk past two-factor authentication into the account as the user, the BKA said. ANY.RUN, which reverse-engineered the kit, found operators could pick one of two modes: a plain PHP page that only harvests credentials, or a Node.js reverse proxy designed to relay the login to Microsoft in real time and capture the resulting session. That second mode is the adversary-in-the-middle technique that has made ordinary MFA a much weaker backstop than it looks. The operation ran like a franchise, with customers the BKA called franchisees. They paid in cryptocurrency and signed up through a dedicated website and a Telegram shop to manage their accounts and organize campaigns, so even low-skill actors could point a working AiTM kit at a target. The authorities put the number of victims since late 2024 in the hundreds of thousands, spread across more than 30 countries and concentrated in Europe and the United States. They estimate the operators earned more than 300,000 euros since 2024, and that each campaign could hit several thousand recipients. Kratos was already being tracked. Microsoft Threat Intelligence identifies the same kit as SneakyLog, a phishing-as-a-service platform it says has run credential-and-2FA theft against Microsoft 365 since at least early 2025, and it caught one campaign in the act. On February 10, operators sent tax-themed emails to about 100 organizations, mostly in the US, across manufacturing, retail, and healthcare, each carrying a W-2 document with a QR code personalized to the recipient that led to a fake Microsoft 365 login. Stolen Microsoft logins are rarely the end of the line. The BKA said the stolen credentials could be used for further phishing, sold to other criminals, or turned into a foothold inside companies by spreading through their Microsoft 365 environments, the familiar path from one phished inbox to business email compromise. Carsten Meywirth, who heads the BKA's cybercrime division, said the operation shows "that even highly professional phishing infrastructures can be effectively combated." The ZIT's Benjamin Krause framed it as proof of the office's "disruptive" approach of dismantling a criminal service outright rather than only charging the people behind it. Microsoft is notifying users caught in the campaigns. For anyone Microsoft is notifying, the fix depends on how they were hit. Where the kit only harvested credentials, a password reset and an MFA check cover it. Where its reverse-proxy mode lifted a live session, that session survives the reset, so it has to be revoked, with high-value accounts moved to phishing-resistant sign-in. Defenders hunting for exposure can look for the kit's tell: ANY.RUN found its login pages almost always load the paired assets barr.svg and lg.svg, then POST stolen credentials to endpoints like next.php or save.php. It rates that pairing at 90% recall with near-zero false positives. For now, the servers are offline and, the BKA says, Kratos-powered campaigns cannot continue. What the takedown did not touch is the roughly 1,800 customers or the kit code they already hold. ANY.RUN found Kratos running on disposable domains, compromised WordPress sites, and hosting shared with other adversary-in-the-middle kits, the kind of setup that reappears under a new name once the servers go down.
thehackernews.comJul 22, 2026extracted
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV. On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components. Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. “A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.” Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company’s review of those apps is “well underway now.” “As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs,” Taylor wrote in an emailed statement. App makers looking for ways to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that turn the user’s device into a residential proxy node that is rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities. Bright Data accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. In a statement shared with KrebsOnSecurity, Bright Data said its network is built on consent and responsibility and operates by LG and Samsung terms. “Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC,” the statement reads. “We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain.” Bright Data and other proxy providers named in Spur’s report all say they follow rigorous know-your-customer processes to validate legitimate uses of their services, which is often heavily tied to content-scraping activities by said customers. The proxy companies also say they incorporate technological countermeasures to prevent proxy service customers from being able to interact with and control other devices on the proxy user’s local network. Spur argues the problem is not that residential proxy networks exist, but rather that they are being embedded at scale in devices that most consumers do not think of as computers and are not equipped to audit. “A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.” LG’s announcement that it is culling residential proxy SDKs from its app store is welcome news, but the company recently came under fire for another questionable partnership: Pimping McAfee security products via software drivers included in its high-end LCD monitors. Earlier this week, the Youtube channel Gamers Nexus showed that certain LG LCD monitors will automatically install an app that promotes paid McAfee antivirus subscriptions, and that the app arrives through Windows Update without an approval prompt. Update, July 22, 1:06 p.m. ET: Added statement from Bright Data.
krebsonsecurity.comJul 22, 2026extracted
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims. On June 19, three different security firms issued similar findings: That NetNut is a residential proxy network which populates a botnet called Popa, and distributes software for devices commonly found in homes, such as smart TVs and streaming boxes. NetNut’s software turns those systems into always-on residential proxy nodes that are rented to others, who predominantly use them to relay abusive and intrusive Internet traffic, such as mass content scraping, advertising fraud, and account takeover activity. Earlier today, NetNut’s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. The seizure notice thanked Google, Lumen, Shadowserver and other industry partners for their help in dismantling hundreds of domains tied to the Popa botnet, which experts say has long been synonymous with NetNut’s residential proxy infrastructure. In a blog post published today, the Google Threat Intelligence Group (GTIG) said NetNut’s proxy network is widely resold and white-labeled by a number of third-party proxy providers, and that its services are heavily sought out by cybercriminals seeking to obfuscate the source of their malicious traffic. The GTIG said that in a single week during June 2026, they observed 316 distinct clusters of threat actors using suspected NetNut exit nodes, including cybercriminal and espionage groups. “These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks,” Google’s GTIG wrote. “Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats.” Google said it disabled Google accounts and services used by NetNut for malware command and control, and that it shared technical intelligence on NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement and research firms. The company also disabled apps known to bundle NetNut’s various SDKs. Omer Weiss, legal counsel for NetNut parent Alarum Technologies, said the company was aware of the FBI seizure and cooperating with investigators. “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account,” Weiss said in a written statement. Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies. Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it. Brundage said NetNut’s apparent demise is likely to be a great disadvantage for the cybercrime community, which was already reeling from legal actions by Google earlier this year that seized infrastructure for NetNut’s biggest competitor — IPIDEA. “I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown,” he said. “Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it.” The NetNut and Popa botnet takedown may have another added benefit, Brundage said: Lessening the impact of large distributed denial-of-service botnets that have been built on the backs of poorly configured residential proxy services. In January, Synthient revealed how cybercriminals had built the world’s largest DDoS botnet (Kimwolf) by tunneling through IPIDEA proxy connections into the local networks of TV box owners, and infecting other Android-based devices behind the victim’s firewall. While many of the bigger proxy providers took steps to block this activity, resellers of the major proxy networks have been far slower to respond to the threat, Brundage said. “In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there,” he said. For its part, Google reckons today’s actions have caused “significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions.” But the company warns that proxy networks can rebuild themselves by effectively reselling other proxy services, as IPIDEA has done over the past few months. “Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes. “While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers.” As KrebsOnSecurity has warned repeatedly, most of the no-name TV streaming boxes for sale on the major e-commerce websites either come pre-installed with residential proxy software, or require the installation of proxy SDKs in order to use the device for its stated purpose (streaming pirated movies, sporting events and TV shows). Google’s advice here is sound: When it comes to TV boxes, stick to name brands from reputable manufacturers, and then be sparing and judicious with any apps you choose to install. The sketchy TV boxes that are being commandeered by the Popa botnet and other threats all come with or require the user to install unofficial Android operating systems that do not operate within the confines of Google’s Official Play Protect store. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following these instructions. Even people without TV streaming boxes can find their smart TVs enrolled in residential proxy networks, just by installing one of thousands of apps available for download on Samsung and LG smart TVs. In a report released last month, the proxy tracking company Spur found 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found. Update, 4:24 p.m. ET: Included a statement shared post-publication from an attorney representing NetNut parent Alarum Technologies. Update, July 8, 2:34 p.m. ET: The website for Alarum Technologies — alarum[.]io — now also features a seizure notice from the FBI. The company’s stock has taken a beating since the FBI action, and is currently trading at $2.62 a share, a roughly 67 percent decline over the past week.
krebsonsecurity.comJul 2, 2026extracted
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone watching a network link. The encryption covers the message inside each packet. The packet still carries plaintext headers, and those values mark a flow as DNS. Agent Beacon: Open-source telemetry layer for AI agents AI coding agents such as Claude Code, Codex CLI, Cursor, and Claude Cowork run on developer laptops, CI jobs, cloud environments, where they edit files, run commands, and call outside tools. Beacon, an open-source project from Asymptote Labs, configures telemetry for those runtimes and writes a normalized record of what each agent does across local, CI, and cloud-agent surfaces. Who pays when you gate cyber-capable AI models? In this interview with Help Net Security, Jaya Baloo, COO & CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down for security teams who depend on the same capabilities for defense. A $1,400 experiment in AI security auditing outperformed OpenAI’s Codex Security A research team has built a system that teaches AI agents to hunt for software bugs by writing the audit method down as plain text. The system, called EVOHUNT, keeps the underlying AI model fixed and improves only an external “playbook” that tells the agent how to work. GTA 6 early access offers are taking gamers’ crypto Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early access for a few hundred dollars in cryptocurrency, ask buyers to enter a payment code, and claim the game will then unlock. Praxen: Open-source AI agent behavior verification Praxen is an open-source tool with a simple job: it checks whether an AI agent does what it claims to do. The tool takes an agent’s declared policy, looks at how the agent operates, and points out every spot where the two drift apart. Where IT meets OT and railway cybersecurity gets harder In this interview with Help Net Security, Jorge Aldegunde, Global Head of Railway Services at DNV, talks through what happens when old operational technology meets newer IT in monorail systems. He explains why open networks widened the attack surface, how teams decide whether to patch a signalling flaw without stopping trains, and who carries the liability. Scoring AI hackers when there is no answer key AI models are solving an increasing number of offensive cybersecurity benchmarks, making those tests less useful for evaluating the most advanced systems. Many rely on vulnerabilities that have already been publicly documented, allowing models to draw on existing knowledge. FrontierCyber, a benchmark from AI security lab Irregular, takes a different approach. It places models on real systems and measures how far they progress toward a security objective. The uptime questions every engineering leader should ask this week In this interview with Help Net Security, Mattias Geniar, CTO at Oh Dear, explains why most outages start quietly, as creeping latency or a slow rise in errors. He argues teams alert on the wrong things: absolute numbers instead of changes, isolated endpoints instead of real user outcomes. Healthcare leaders see a fatal cyber incident as inevitable Healthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, and a cloud provider stores data. Every one of those connections gives an outside company a path into the practice, and any one of them can break. According to Omega Systems’ 2026 Healthcare IT Landscape Report, the large majority of practices dealt with at least one operational disruption that traced back to a vendor or a vendor’s own supplier. Two CEOs on why security and AI readiness belong together SuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time and context lost to tool-switching, lowers costs against multi-vendor setups, and helps close the gap between average MSP margins of 8% and the 18% top performers reach. What the Fortibleed campaign means for organizations running FortiGate firewalls A massive credential-harvesting campaign targeting FortiGate firewalls has exposed thousands of organizations to potential network compromise, and a trove of attacker tools, scripts, and credentials left inadvertently exposed on a server has given researchers an unusually detailed look at how the operation worked. Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. Law enforcement hits StealC and Amadey malware networks Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. Mystery hackers use novel SharkLoader dropper against governments, software devs Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. Synology issues critical fix for MailPlus Server vulnerabilities Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. Details about the vulnerabilities are still under wraps. Product showcase: How to evaluate AI SOC platforms and where Prophet AI leads The agentic SOC market is crowded with vendors promising to automate alert triage, investigation, and response. The challenge is separating measurable operational gains from marketing claims. Prophet Security is an agentic AI SOC platform that autonomously triages, investigates, and responds to security alerts. It also helps strengthen detection and response programs by identifying tuning opportunities, uncovering detection gaps, and enabling natural-language threat hunting. 23 ClawHub plugins squatting official scopes expose AI registry security gaps In this Help Net Security video, Ax Sharma, Head of Research at Manifold Security, breaks down how 23 code-executing plugins ended up under ClawHub’s official @openclaw and @clawhub scopes while owned by unrelated accounts, why an official-looking scope is a supply chain risk even when the code isn’t malicious, and what the registry changed after the disclosure. What your next cyber insurance renewal will demand In this Help Net Security video, Michael Loewy, co-founder, Tide Foundation, explains how cyber insurance is rewriting security programs at renewal time. Hundreds of AI-powered iOS apps found exposing credentials Mobile app developers are packing AI features into everything from writing assistants to productivity tools and lifestyle apps. New research shows that securing access to those services remains a challenge. Researchers from Wake Forest University analyzed 444 iOS applications with LLM features and found 282 that exposed exploitable credentials or backend access mechanisms. Free, no-signup World Cup streams serve scams instead of football Researchers at Malwarebytes identified dozens of websites claiming to offer free access to FIFA World Cup matches. Instead of streaming games, the sites directed visitors through a chain of advertising pages designed to generate revenue for their operators. Phishing hides in routine Microsoft 365 workflows Attackers are abusing Outlook Groups and Microsoft 365 collaboration features to make phishing campaigns appear routine, according to Fortra. The attack begins when a target is added to or invited into an attacker-controlled Microsoft 365 Group. The group’s name, description, or welcome message is designed to create urgency, often using themes such as payroll updates, contract renewals, supplier requests, or mandatory training notices. Two Scattered Spider hackers plead guilty over Transport for London cyberattack Two members of the notorious hacker group Scattered Spider have pleaded guilty to charges related to a 2024 cyberattack on Transport for London (TfL) that resulted in £29 million in loss and recovery costs. Using Reddit to manipulate AI search results is surprisingly easy A Reddit comment that takes only a few seconds to write can end up influencing the answers generated by AI research tools. A Cornell Tech study found that a short snippet of user-generated text, sometimes as little as 13 words, was enough to affect the output of deep-research agents, AI systems that search the web, gather information from multiple sources, and generate reports with citations. LastPass customer data exposed through Klue supply chain attack LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. Phishing attack on healthcare firm Xsolis impacts 1.4 million people Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. Algerian national accused of running cybercrime marketplaces extradited to US An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges. WhatsApp will warn users before they message a potential scammer WhatsApp is rolling out a warning screen on Android and iOS that appears before users open chats with unfamiliar phone numbers. Meta hopes that this new feature will help users avoid scammers. Hacker gets 18 months for attack that compromised 60,000 betting accounts A 21-year-old man known online as “Snoopy” was sentenced to 18 months in prison for his role in a scheme that hacked user accounts on a fantasy sports and betting website and sold access to them, causing hundreds of thousands of dollars in losses. Stealthy new backdoor surfaces in attacks on multiple sectors A relatively new backdoor called Mistic has been deployed in multiple attacks since April 2026 targeting organizations in the insurance, education, IT, and professional services sectors, according to Symantec. A privacy-first take on local malware analysis Submitting a suspicious file to VirusTotal or MalwareBazaar uploads a copy to a searchable public repository. While these platforms help analysts quickly identify malicious files, they also allow threat actors to see when their tools have been detected by monitoring for matching hashes. In targeted attacks, uploaded samples may also contain sensitive victim data, exposing it to third-party systems. Burnyard, a research project from The Ohio State University takes aim at this condition. It runs suspicious binaries on the analyst’s own hardware and keeps each sample local for the duration of the analysis. Microsoft gives Windows 10 users an unexpected extra year of free security updates Microsoft has given Windows 10 users another year of free security updates, extending its consumer Extended Security Updates (ESU) program until October 12, 2027. SIM-swapping gang busted in international police operation Officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of SIM swap attacks, cryptocurrency theft, and money laundering. Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra. The systemd 261 release brings a software TPM, new OS installer Linux distributions that ship systemd as their init system now have a new version to track. The systemd 261 update adds a cloud metadata subsystem, carries process state through kexec reboots, and continues a long-running effort to load external libraries on demand. Product showcase: Avira Security for iOS blends security, privacy, and device optimization Avira Mobile Security for iOS combines security, privacy, and device optimization tools in a single application. The app is also available for Android, macOS, and Windows devices. Only 7% of companies are ready for the AI agents they deployed Most organizations now run or pilot AI agents that operate on company data with limited human direction at each step, a share that reaches 88% in Veeam Software’s Data and AI Trust Gap report. The systems that are supposed to keep an eye on them have not caught up. Residential proxy SDKs are hiding in LG and Samsung smart TV apps Smart TVs in living rooms run small apps that show fish tanks, clocks, solitaire games, and slideshows of puppies. A share of those apps can also send other people’s internet traffic out through the home connection. Spur Intelligence scanned 6,038 apps across LG webOS and Samsung Tizen and found 2,058 that contain residential proxy software. OpenAI wants AI to fix vulnerabilities, not just find them OpenAI expanded Daybreak, its cybersecurity initiative that combines AI models, Codex Security, security researchers, maintainers, industry partners, and access controls to support vulnerability discovery and remediation. Organizations can use the initiative to identify, validate, and fix software vulnerabilities, while developers, maintainers, and security teams can use its tools to strengthen defensive security capabilities. Security testing was built for a slower world Software teams are pushing code into production faster than security testing can keep up. AI is accelerating development cycles and adding pressure to security programs that rely on periodic validation and manual penetration testing. The 2026 State of AI Security Testing report from Aikido Security found that 76% of organizations have had to stop, restrict, or roll back AI-driven behavior in the past 12 months. Google Workspace expands password reset alerts to all admins Google’s Alert Center, a dashboard in the Google Admin console that displays security and administrative alerts and helps administrators identify, investigate, and respond to issues affecting their organization, is expanding the “Super Admin password reset” alert into the “Admin password reset” alert. The feature is rolling out gradually and will be available to all Google Workspace customers. Anthropic’s Claude Tag gives AI agents independent identities Anthropic introduced an agent identity model for Claude Tag, its AI assistant designed for team collaboration in shared workspaces. The model gives Claude its own identity, permissions, and tool access, configured by administrators and tied to a workspace or channel. Most teams will ship AI-written infrastructure code with little review AI-assisted development has settled into everyday practice across software organizations, and developers using it move from idea to working code in hours. That code does not stay with the developers who prompt it. It flows downstream to the DevOps and platform teams who deploy and maintain it, and those teams are not getting the same speed boost. Best practices for AI in open-source work Free and open source software developers us AI coding assistants such as Claude Code, Copilot CLI, Antigravity, and OpenCode in their daily work. The Software Freedom Conservancy responded to that trend with a set of recommendations for contributors who use these tools, which it groups under the label LLM-gen-AI, meaning generative AI systems backed by LLMs. LLM security advice looks solid until you check the hard cases Plenty of people now type their security worries straight into a chatbot. A hacked account, a suspicious email, a stalker who might be tracking a phone, all of it lands in the same window someone would use to ask about dinner. A benchmark called HelpBench tests how well chatbots handle those moments, and the results give security professionals something to watch in what their users are being told. Google Wallet adds TSA Touchless ID for faster airport screening Google Wallet has joined the Transportation Security Administration’s (TSA) PreCheck Touchless ID program, allowing travelers to pass through security checkpoints using the TSA’s facial comparison technology. The system verifies identity by matching a live photo taken at a checkpoint with identity and flight information, reducing the need to present a physical ID. Modelplane: Open-source control plane for AI inference Organizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model placement, replica scaling, infrastructure provisioning, weight distribution, and traffic routing. Teams have built this coordination layer by hand, one operator at a time. Upbound, the company behind the Crossplane project, released Modelplane, an open-source control plane that manages fleet-wide coordination for AI inference. Ransomware gangs find Europe’s weakest link in third-party suppliers Ransomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026 European Cyber Risk Report. Critical open-source projects get a new security framework Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial institutions, security vendors, AI companies, and open source projects to support the remediation and disclosure of vulnerabilities affecting widely used open source software. Cybersecurity jobs available right now: June 24, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the month: June 2026 Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI.
helpnetsecurity.comJun 28, 2026extracted
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishing pipes because apparently email was not enough hell already. The worst part is how cheap some of it feels. Not elite. Not cinematic. Just stale secrets, fake updates, lazy trust, and random boxes quietly becoming someone else’s infrastructure. Same internet, fresh headache. Let’s get into it. Privacy-first bot defenseCloudflare has teamed up with Google Chrome, Microsoft Edge, and Mozilla Firefox to create a privacy-preserving protocol that websites can use to separate desirable web traffic from undesirable network requests. This involves the use of Private Access Control Tokens (PACT), which allow websites to issue anonymous tokens that assert a given browsing session is being run by a human. "A user's browser can then provide these tokens to other sites to prove that a human is in the loop, reducing the need for annoying and clunky captchas or invasive tracking," Cloudflare said. "PACT is designed so that sites cannot leverage it to track or identify users or their browsing history." Six curl CVEsAISLE said it discovered six vulnerabilities in curl, which range from "classic memory-lifetime issues to logic bugs in how libcurl decides whether a connection, credential, or host identity is still valid." One of the notable vulnerabilities is CVE-2026-8932, which allows the library to "reuse a previously created connection even when some mTLS config-related option had been changed that should have prohibited reuse." AISLE described it as the oldest curl vulnerability reported so far, adding that it has been shipped in releases since curl version 7.7, which was released on March 22, 2001. The identified flaws have been addressed in version 8.21.0. Unauthenticated takeoverA critical security flaw has been disclosed in self-hosted versions of Hoppscotch(CVE-2026-50160, CVSS score: 10.0), an open source API platform, that can result in complete compromise. Offgrid Security's autonomous AI security agent, Kiro, has been credited with discovering the bug. "The POST /v1/onboarding/config endpoint allows an unauthenticated attacker to inject arbitrary InfraConfig keys -- including JWT_SECRET and SESSION_SECRET -- into the database via mass assignment," the project maintainers said. "These keys are not declared in the SaveOnboardingConfigRequest DTO, but because the NestJS ValidationPipe does not strip extra properties, they pass through to the service layer, where Object.entries(dto) iterates all keys without restriction." A successful exploitation leads to full server compromise and persistent access that survives password resets. OffGrid Security told The Hacker News that four independent weaknesses are combined to allow an unauthenticated attacker to overwrite the JWT signing key in a single HTTP request, and the exploit requires no credentials. The issue has been fixed in hoppscotch-backend version 2026.5.0. Proxyware in smart TVsA new report from Spur Intelligence has revealed that more than one-third of LG and Samsung smart TV apps it reviewed contain proxyware that can relay third-party traffic through the TV owner's internet connection with users' consent. The company said it scanned 6,038 apps across LG webOS and Samsung Tizen and found 2,058 that contain residential proxy software. This includes clocks, screensavers, games, fish tanks, and other low-utility apps. On LG webOS, 42.5% of apps carried such code. On Samsung Tizen, the rate was 26.9%. Across both platforms, it reached 34.1%. Bright Data, Massive, and Oxylabs take up the top three SDK providers for webOS and Tizen. "Smart TVs are almost ideal proxy hosts. They sit on the same home network as everything else, but they do not feel like computers, so people rarely audit them like computers," Spur said. "There is no battery drain to notice, no cellular bill to spike, no app switcher full of suspicious background activity. A TV can stay plugged in, signed in, and online for years while the user thinks of it as furniture." The threat intelligence firm said this dynamic also changes the consent equation, as users may not realize what it actually means to sell access to their residential IP address. "Technically, these applications are compliant with gaining consent based on how they inform the user," Spur CTO Alastair Parr told The Hacker News. "However, there is often no verification that the user is either of age or authorized to provide consent on the device. The reality is that there are likely many smart TVs scattered across office spaces and residential homes, quietly part of these networks, without the responsible owners' awareness or consent." Amazon's Device and System Abuse Policy explicitly bars apps that facilitate proxy services for third parties. Similar protections have been enabled by Roku as well. However, LG and Samsung are yet to enforce an equivalent policy. Edgecution via TeamsAn initial access broker (IAB) affiliated with Payouts King ransomware has been observed masquerading as IT personnel in social engineering attacks conducted via Microsoft Teams to deliver a malicious Microsoft Edge browser extension dubbed Edgecution. "The technique utilizes a malicious Microsoft Edge browser extension that exploits the Chrome native messaging protocol to interact with host-native applications beyond the confines of the browser sandbox," Zscaler ThreatLabz said. "By abusing this interface, the attackers gain direct host access, enabling them to manipulate the local filesystem, launch processes, and execute arbitrary code on the compromised host." The malware has two components: a Microsoft Edge browser extension named "Edge Monitoring Agent" that beacons to a command-and-control (C2) server and relays host-based commands to a Python-based backdoor, which can collect system information, enumerate running processes, provide filesystem access, and execute arbitrary Python code and shell commands. The extension will be invisible to a user as it's loaded in a headless Microsoft Edge browser. A similar attack chain involving a Chromium-based extension codenamed SNOWBELT was detailed by Google-owned Mandiant in April 2026. Legacy credential breachCompetitive intelligence company Klue has revealed that a credential dating back to 2022, which was used as part of a limited pilot, was exploited by the Icarus extortionists to steal Salesforce data from its corporate customers, including several cybersecurity companies. In a statement shared with TechCrunch, the company said the credential was "originally provided to a third-party in 2022, for a limited pilot." Klue did not share specifics about the purpose of the pilot, the duration for which it ran, or the identity of the third-party to whom the company gave the credentials. It's also unclear why the credential wasn't revoked immediately, assuming the pilot had concluded. Questions remain about how the attackers managed to acquire this legacy credential in the first place. A number of companies have come forward to confirm they have had limited Salesforce information stolen during the attack, including 8x8, BeyondTrust, Gong, Jamf, HackerOne, Insurity, LastPass, OneTrust, Pendo, Recorded Future, Snyk, Sprout Social, and Tanium. State-crime convergenceNCC Group said it has found growing evidence of nation-state actors increasingly leveraging tools and tactics traditionally associated with financially motivated cybercrime to disguise their espionage and intelligence-gathering operations, blurring the line between the two sets of activities. "Historically, organisations could draw a relatively clear distinction between ransomware attacks driven by financial gain and nation-state operations designed to support strategic objectives. That distinction is becoming increasingly difficult to make," Matt Hull, VP of Cyber Intelligence and Response at NCC Group, said. "What we're seeing is a convergence of criminal and state-backed activity. Threat actors are sharing infrastructure, adopting common tooling and, in some cases, deliberately operating behind established ransomware brands to obscure attribution and delay response efforts." Admin reset alertsGoogle said it's expanding the existing "Super Admin password reset" alert into a broader Admin password reset alert in Alert Center. "Previously, this rule only triggered alerts when a super admin's password was changed," the company said. "With this update, the alert will now cover password resets for all administrator roles within your organization. This update provides admins with better visibility and control over the security of their organization's privileged accounts. Monitoring password changes for all admin roles provides a higher level of oversight to respond more quickly to potential account compromises or unauthorized changes." The change is applicable to all Google Workspace customers. ClickFix targets macOSA new ClickFix campaign has been observed tricking users into copying malicious commands and pasting them to the Terminal app that silently downloads and mounts a malicious DMG file. The disk image file contains a self-signed information stealer that can harvest a user's system password, data from web browsers, wallets, messaging apps, and Keychain, exfiltrate the data, set up LaunchAgent persistence, and tamper with Ledger Live and Trezor Suite installations by replacing legitimate components to hijack cryptocurrency wallet information. The stealer is assessed to belong to the Atomic macOS Stealer (AMOS) lineage, particularly a variant called Odyssey, per Palo Alto Networks Unit 42. The development comes as the cybersecurity company detailed another multi-step ClickFix attack that employs techniques like brandsquatting to deliver a cross-platform trojan with browser-credential stealing, remote shell, live screen streaming, keylogger, file manager, and SSH tunneling capabilities. TfL hackers convictedThalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, have been convicted in the U.K. for orchestrating a cyber attack on Transport for London (TfL) in 2024, costing $38.2 million in losses. The two defendants, who were members of the online criminal collective known as Scattered Spider, were arrested last September but pleaded not guilty to their crimes during a court appearance in November 2025. They are now scheduled for sentencing on July 16, 2026. "Scattered Spider is a prolific criminal group that engages in data extortion and other criminal activities, utilizing social engineering techniques and SIM swap attacks, to obtain credentials, install remote access tools, and/or bypass multi-factor authentication," the U.S. Federal Bureau of Investigation (FBI) said. Marketplace admin extraditedAbdellah Belmili (aka Dila Belmili or SPOX), a 26-year-old Algerian national, has been arrested, charged, and extradited from Spain to the U.S. on charges of conspiracy to commit bank fraud. SPOX is alleged to have acted as an administrator for a cybercrime marketplace ("www.market0day[.]com") as well as created phishing kits that have been used to compromise major U.S. financial institutions. "Between September and November 2020, Belmili advertised the marketplace and facilitated some of the customer support for the marketplace on his personal Telegram channel @SpoxCoder," the U.S. Justice Department said. "In late December 2020, after several customers complained that they had not received their purchases from www.market0day[.]com, Belmili replied that he was no longer the administrator, and instead had opened up a new marketplace – www.spoxy[.]us, advertising the new marketplace – www.spoxy.us, advertising the new marketplace as a 'new store for bulk SMS.' 'Bulk SMS' typically refers to sending phishing or other fraudulent messages via text message." Approximately 5,600 U.S. and international victims have been identified. Collaboration phishingA new phishing campaign is abusing Outlook Groups and Microsoft 365 collaboration features to "make malicious activity appear routine," Fortra said. The attack involves adding targets to an attacker-controlled Microsoft 365 group and then using the group mailbox, shared files, or fake calendar invites (aka CalPhishing) to facilitate credential theft, token capture, or malware delivery. "The technique shifts malicious intent away from a single phishing email into a trusted productivity workflow," the company said. "A user may see what looks like a normal group addition, internal update, shared resource, or calendar item before being pushed toward an action." AI in cybercrimeA new analysis from Sophos has revealed that AI has emerged as a hot button topic in underground communities, as threat actors debate its potential for malware and tool development, while some express concerns about the technology reducing work opportunities. This includes posts selling API keys for generative AI tools, advertising solutions that can enhance social engineering, AI-enabled malware (e.g., ApexAI, Metatron, and PolyEngine), discussing jailbreaks for public AI models to bypass censorship and other safeguards using techniques like role-play framing, multi-stage prompting, and contextual manipulation, and offers to hire or partner with prompt engineers. Threat actors have also discussed the use of public AI assistants for intrusion activity, as well as marketed a tool called Leak Bazaar that claims to use AI to triage and sift through mountains of stolen data before it can be packaged and exchanged with other threat actors. Not all have embraced AI with open arms, however, with some outlining skepticism and worries about how the rise of AI could "reshape roles, pricing, and competitive advantage within the cybercrime economy." 8,500 REDCap instancesCensys has uncovered just over 8,500 REDCap instances globally as of June 16, 2026, with most of them located in the U.S., the U.K., Germany, and Australia. REDCap, short for Research Electronic Data Capture, is a web application used by research institutions globally to hold clinical trial data, participant records, and other sensitive research information. Last week, Google Threat Intelligence Group (GTIG) attributed a year-plus espionage campaign against North American academic, medical, and military research institutions to UNC6508, a China-nexus actor. The intrusion set leveraged internet-facing REDCap servers as an initial access vector to deploy a backdoor called INFINITERED to exfiltrate sensitive data. Exactly how these servers are hacked is unconfirmed. The earliest known compromise dates to September 2023. Surveillance export gapsA report from Human Rights Watch has revealed that a Bulgaria-based surveillance technology firm named Circles sold its tools to countries that were likely to use them for repression or to commit serious human rights violations. Documents describe licenses for exports of Circles' technology to Azerbaijan, Bahrain, Brazil, Dominican Republic, El Salvador, Ghana, Guatemala, Israel, Jordan, Malaysia, Mexico, Morocco, Panama, Serbia, and the U.A.E. Clients included intelligence services, military and police bodies, regional governments, and private companies, Human Rights Watch said. That said, it's currently not known whether the technology was actually exported. "Nonetheless, issuing the licenses demonstrates a major flaw in how individual governments implement E.U. export controls for surveillance technology," the non-profit said. "The controls are intended to limit exports of surveillance technology to destinations where there is a likelihood it could be used to violate rights, and to provide transparency about what exports take place." BitB malware luresA campaign that impersonates popular software brand names has leveraged the Browser-in-the-Browser (BitB) technique to distribute malicious payloads by means of a reusable phishing kit. It makes use of a draggable pop-up with a spoofed URL to serve a fake software update warning. "The campaign uses social engineering to trick victims into downloading and manually executing a malicious installer (e.g., an .exe payload)," Unit 42 said. "The pages simulate a stalled document load and present an 'out of date' software error." Earlier this month, Unit 42 disclosed details of a second BitB campaign involving at least 10 unique domains that was used to steal Microsoft 365 credentials using a draggable, OS/browser-fingerprinted pop-up with a spoofed OAuth URL. In this attack, victims who click a Microsoft sign-in button are presented with what appears to be a standard login page designed to harvest credentials. If there’s a theme here, it’s that attackers do not need magic when the boring crap still works — forgotten creds, lazy trust, fake updates, loose admin paths, and users getting nudged into doing the dangerous part themselves. The future is here, somehow, and it still smells like a misconfigured staging box. Patch what you can. Revoke what you forgot. Maybe glance at the devices you’ve been treating like furniture. See you next ThreatsDay, assuming the internet hasn’t found an even dumber way to catch fire by then.
thehackernews.comJun 25, 2026extracted
Residential proxy SDKs are hiding in LG and Samsung smart TV apps
Residential proxy SDKs are hiding in LG and Samsung smart TV apps Smart TVs in living rooms run small apps that show fish tanks, clocks, solitaire games, and slideshows of puppies. A share of those apps can also send other people’s internet traffic out through the home connection. Spur Intelligence scanned 6,038 apps across LG webOS and Samsung Tizen and found 2,058 that contain residential proxy software. On LG webOS, 42.5 percent of apps carried such code. On Samsung Tizen, the rate was 26.9 percent. Across both platforms it reached 34.1 percent. What a residential proxy SDK does A residential proxy lets a third party send web requests that appear to originate from a home internet connection. Embedded in a TV app, the SDK uses the device’s network link to carry that traffic. The visible app stays calm and ad-light. The connection earns money in the background. “Smart TVs are almost ideal proxy hosts. They sit on the same home network as everything else, but they do not feel like computers, so people rarely audit them like computers. There is no battery drain to notice, no cellular bill to spike, no app switcher full of suspicious background activity. A TV can stay plugged in, signed in, and online for years while the user thinks of it as furniture,” Trevor Sutter from Spur Intelligence explained. Consent given once The proxy software asks permission a single time. All three prompts in the dataset state that the proxy keeps running after the app closes. A Bright Data prompt in a game called Galactic Harmony offers ad-free play in exchange for letting the company use the device’s IP address for web indexing. A Pac-Man title on Tizen presents the same exchange. Galactic Harmony notice (Source: Spur Intelligence) Who publishes the apps “Bright Data, Bright Data Ltd, and Bright SDK account for 367 proxy-flagged apps in the dataset. Honeygain UAB (subsidiary of Oxylabs) shows up as the publisher on another 16,” Sutter said. Some of the inventory consists of thin shovelware games, screensavers, and utility shells shipped at scale so the software has somewhere to run. The app serves as the wrapper. The residential IP address is the product. How platforms compare Amazon prohibits this category through its Device and System Abuse Policy, which bars apps that facilitate proxy services for third parties. Roku reportedly bars developers from using Bright SDK and similar services, and affected apps disappeared after the company was contacted. LG and Samsung have yet to publish an equivalent policy, and the same business model continues to appear at scale on webOS and Tizen. Risk to the home network A TV app acting as a proxy runs inside the home network. If a provider permits requests to private or local addresses, or if filtering fails, the device can reach router admin panels, NAS devices, printers, cameras, and developer machines. The Bright Data sample ships with a blocklist covering private ranges including 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. The local Massive and Honeygain/Oxylabs samples lacked a comparable private-range blocklist. The provider’s filtering and customer vetting form the boundary, and the device owner lacks any means to verify it from the TV. How the apps were identified “We did not rely on store descriptions or permission prompts. We downloaded the actual LG webOS and Samsung Tizen app packages, unpacked them, and scanned the files inside. The fingerprints looked for confirmed SDK artifacts: Bright Data brd_api.js and brd_sdk services, Massive clients and .massivesdk services, Honeygain/Oxylabs SDK files and service names, and related tokens or package names. Every app counted there had a confirmed proxy SDK fingerprint,” Sutter said. Vendor responses Bright Data, Massive, and Oxylabs responded before publication. Bright Data said consent and independent audits separate a legitimate network from a harmful one, and that it approves use only for verified business, research, and journalistic purposes. Massive said its network users pass a Know Your Customer process and that its technical controls operate server-side. Oxylabs said it restricts access to private and local ranges through filtering, traffic inspection, and blocklists, and that only applications approved through its Honeygain SDK Partnership Program enter its proxy network. “The proxy providers contacted for this research emphasized customer vetting, traffic restrictions, and abuse-prevention controls. Those controls may reduce risk, but they do not change the underlying reality that residential proxy infrastructure is being embedded at scale in devices that most consumers do not recognize as participating in such networks,” Sutter concluded.
helpnetsecurity.comJun 23, 2026extracted
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. Popa is a massive botnet, but by all accounts it is unlike traditional botnets that enlist compromised systems in destructive activities, such as coordinating huge distributed denial-of-service attacks. Rather, Popa appears designed with a singular purpose: Implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connections, and opening communication tunnels on demand. Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes. These devices, which are marketed under thousands of brand names and model numbers and broadly available for purchase at top e-commerce destinations, all advertise the ability to stream hundreds of subscription video services for an up front one-time fee. But as the FBI and security industry experts have warned repeatedly, these streaming boxes typically bundle or come pre-installed with software that turns the user’s TV into a “residential proxy” — allowing anyone to route their Internet traffic through that device for as long as it remains plugged into a wall socket and connected to a local network. More concerning, some of these proxy networks do little to stop malicious customers from communicating with and even compromising systems on the local network of the unsuspecting device owner. The first clues about Popa’s origins came in a 2025 report from the Chinese security company XLAB, which flagged at least nine domain names that were used to register and direct the activities of compromised devices. In a report released today, the security firm Qurium described how it stumbled on some of those same domains while investigating a series of disruptive and expensive data scraping events targeting the company’s hosted organizations in May 2026, in which the scraping activity was scattered evenly across more than 1.4 million Internet addresses. Qurium said it found several dozen domains used to control Popa that were all hosted in lockstep across multiple Internet addresses over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Digging deeper, Qurium discovered gmslb[.]net was referenced in dozens of pirated or modded video content streaming apps, such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob and HD/OceanStreams. Qurium’s report notes that most of the domains long used to control the Popa botnet were seized or dismantled in July 2025, after Google, HUMAN Security and Trend Micro teamed up to disrupt Badbox 2.0, a botnet that is closely associated with Vo1d. Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io. Ninjatech is a company founded by Moishi Kramer, whose LinkedIn profile says he is vice president of research and development at NetNut. That resume credits Kramer for helping NetNut to build from the “ground up,” “designing the architecture,” and “scaling the NetNut” before the company was acquired by Alarum Technologies. A self-created listing at the job board F6S references Kramer as the sole owner of the Ninjatech domain (a screen capture of it is pictured below). Responding via email, Mr. Kramer said Ninjatech ceased operations approximately five years ago, when the company sold a software development kit (SDK) called Popa that was designed to use a small portion of a device’s bandwidth and to run only after the host application obtained user consent. “That code was sold and licensed to third parties including resellers years ago,” Kramer said. “Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.” Kramer said neither he nor NetNut builds, operates or maintains the infrastructure being described as Popa, nor does he control the Ninjatech domain. “I didn’t register the June 2025 domains you mention, and I don’t know who did,” he continued. “I have no control over, or visibility into, that infrastructure. I can only tell you it isn’t operated by me or by NetNut.” But in a separate Popa research report released today, the proxy-tracking company Synthient said a recent analysis of the Popa SDK revealed outbound traffic clearly associated with NetNut. “The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients,” Synthient wrote. “This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.” Alarum Technologies, NetNut’s Tel Aviv-based parent company, said the reports by Synthient and Qurium contained “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” Alarum shared a statement saying they reject the basic characterization of the SDKs and technologies discussed in the reports as a “botnet.” “The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate,” the statement reads. “Netnut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services.” Alarum said NetNut places “significant emphasis on appropriate notice and consent mechanisms, conducts customer due diligence, monitors for potential misuse, and takes steps intended to detect and mitigate suspicious or unauthorized activity.” “This method of operation is supported both by internal procedures and policies, including performing KYC checks and additional due diligence of NetNut’s customers, as well as employing various technological measures, designed to assist in identifying and addressing suspected misuse of the network,” their statement continued. However, in a report released on June 8, the proxy tracking service Spur asserted that NetNut does not require corporate verification or meaningful “know your customer” procedures before allowing customers to purchase proxy access. “An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in,” Spur wrote. “The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies.” “Nor is NetNut the only front door,” Spur continued. “A number of downstream white labelers and resellers repackage the same ISP proxy pool under their own brands. These outlets typically perform no KYC at all, less scrutiny than NetNut itself, who at the very least might assign an account manager to potential users. Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto.” Synthient found that although the most recent builds of Popa (as of three months ago) have added the ability to ask the user for consent before installing proxy components, not all variants or previous versions of Popa contain this functionality. “Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent,” Sythient wrote. THE PREVALENCE OF POPA Chris Formosa is senior lead information security engineer for Black Lotus Labs, a division of the Internet backbone carrier Lumen Technologies. “What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing,” Formosa said, explaining that many other proxy services simply resell NetNut proxies rather than building out their own far-flung proxy networks. “So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently.” Formosa said the Popa botnet averages between 1.5 million to 2.5 million distinct IP addresses each day, relying on between 250 and 300 Internet addresses that are used to direct its activities. “That’s why Popa is so dangerous,” Formosa said. “It may not be the largest botnet we have seen, but it is spread all over the industry, making its power very amplified.” Formosa said while that makes Popa one of the larger botnets out there today, its numbers pale in comparison to those previously boasted by IPIDEA, a China-based proxy provider that until recently operated a daily pool of nearly 10 million devices that they resold as proxies to anyone. In January 2026, Synthient published research showing that multiple new large DDoS botnets had grown rapidly by tunneling through IPIDEA proxies into the local networks of unsuspecting TV box owners and infecting other Android-based devices behind the user’s firewall. IPIDEA is based largely on SDKs used to view pirated streaming content on a vast number of TV box devices, but the service’s numbers have dwindled since January, when Google and industry partners took legal action to seize domain names that IPIDEA used to control devices and proxy traffic through them. Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates. Meyer told KrebsOnSecurity that Nokia is monitoring 26 of at least 359 known relay nodes for the botnet, and estimates that each relay node handles between 35,000 and 60,000 clients simultaneously. “On the relay node subset I am looking at (26 of them), 750,000 unique sources in 24 hours,” Meyer wrote in response to questions. Nokia Deepfield released its own report today on RoboVPN, a VPN app tied to the Vo1d botnet’s Popa plugin that Qurium attributes to NetNut/Alarum Technologies. THE SYMBIOSIS OF PROXIES AND DATA SCRAPING Experts say many of the world’s largest proxy providers have updated their public-facing branding to highlight their utility for training AI platforms, implying it is a primary use case for their residential proxies. That’s because AI services tend to rely on constantly mass-scraping the Internet for new text, images and video content that can be used to train large language models (LLMs). “AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search,” reads a report this month from Include Security that examines the prevalence of proxy SDKs in smart TV apps. “But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer.” This non-stop content scraping has spawned more than 70 copyright infringement lawsuits against major tech companies that have acknowledged large-scale data scraping as a major source of the “brains” behind their commercial AI offerings. Ironically, much of that scraping is being aided by proxy services that are intimately tied to unofficial Android TV boxes and associated SDKs whose stated purpose is streaming pirated content. The scraping activity has become so aggressive that it often overwhelms the targeted websites, preventing them from being reachable by legitimate visitors. In many reported cases, nonprofit organizations, libraries and universities have complained of constantly battling to keep their services online in the face of relentless data-scraping firms hiding behind residential proxy services. A survey conducted last year by the Confederation of Open Access Repositories (COAR) found while some content scraping bots are rather innocuous, “others are sufficiently aggressive that they are increasingly causing service disruptions in repositories and other scholarly communications infrastructures.” More than 90 percent of survey respondents indicated their repository is encountering aggressive bots, usually more than once a week, and often leading to slow downs and service outages. “Automated web scraping is nothing new, and has been the key technology underlying search engines such as Google for over 30 years,” wrote Brendan O’Connell, platform manager at the Directory of Open Access Journals (DOAJ), a free, community-curated index of peer-reviewed academic journals. “However, the current investor-fueled AI startup craze means there are now thousands of well-funded companies developing and deploying their own scraping tools to train AI models, alongside existing major players like OpenAI and Google.” DON’T TOUCH THAT DIAL! Across the United States, local communities are pushing back against the proliferation of new data centers aimed primarily at improving the capabilities of AI. But security experts say the general public remains largely unaware that using one of these unsanctioned Android TV boxes means their “smart TV” is almost certainly using a significant amount of bandwidth each month to help train modern AI models. Even households without these sketchy TV boxes can still have their smart TVs turned into residential proxy nodes, just by downloading one of thousands of apps made available on Samsung and LG smart TVs. Spur said it recently scraped the LG and Samsung app stores and found that each had approximately 3,000 apps available for download. Many of these apps are simple games or utilities that state in the fine print that the user’s Internet connection will be used to download data and that they can opt out at any time. Spur said it found that more than 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found. Experts say it’s questionable whether TV apps with proxy SDKs can obtain meaningful consent from users for installing an always-on proxy connection, particularly when anyone in a household — including children — can effectively opt the family TV into a residential proxy network just by installing a simple game or app. “Privacy-policy disclosure is the wrong control surface for a TV,” Include Security wrote. “It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog doesn’t convey that a paying customer is about to route their scraping traffic through the user’s home internet.” Spur’s head of research Sean Simmons told KrebsOnSecurity that most people do not have a working mental model for what it means to sell access to their residential IP address, no matter what device they are using. “And on a TV, the gap is even wider,” Simmons said. “A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted.” Simmons said LG and Samsung should follow the lead of other TV platforms that have already drawn a line against residential proxy providers, pointing to policies by Amazon that prohibit apps facilitating proxy services for third parties. Likewise the TV streaming device maker Roku reportedly now bars developers from using proxy SDKs and has removed apps that bundled them. Apps that turn one’s device into a residential proxy node are not limited to smart TVs and no-name streaming boxes, of course. As noted by the security firm Infoblox, mobile app developers can embed SDKs provided by the residential proxy networks into their products to monetize their software, allowing them to receive a small amount of money on each installation. The result, Infoblox said, is that devices are frequently enrolled without the owner’s knowledge, typically through free applications such as VPNs, streaming apps, screensavers and “productivity” apps such as PDF viewers and break reminders. All too often, these proxy services are beaconing out from employee devices brought into the workplace, Infoblox found. In a blog post earlier this month, Infoblox said it discovered that fully 65% of its customer base was querying one or more residential proxy related domains. “We saw steady growth in these queries in 2025, with a 25% increase over the year to over 500 billion per month,” Infoblox wrote. “Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators. Perhaps even more concerning is that over 60% of government and banking customers have as well.” Infoblox researchers Nick Sundvall and David Brunsdon warned that with residential proxies in the corporate environment, external access is granted to an organization’s IP space. “If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source,” they wrote. “Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation. The stunning prevalence of these services within customer environments warrants attention from both network defenders and policy makers who should consider how the risks posed by residential proxies could be impacting their security posture.”
krebsonsecurity.comJun 18, 2026extracted
Coupang, in arrivo multa record da 410 milioni di dollari per il data breach del 2025
In Corea del Sud si tratta della sanzione più elevata mai comminata contro un’azienda per data breach. La Corea del Sud infliggerà al gigante dell’e-commerce Coupang una multa di 625 miliardi di won (409,30 milioni di dollari) a seguito del data breach dello scorso anno. Si tratta della sanzione più elevata mai comminata nel Paese contro un’azienda per una violazione simile. La Commissione per la protezione dei dati personali ha dichiarato che la società quotata a New York ha divulgato i dati personali di oltre 33 milioni di clienti. A rendere particolarmente grave la situazione, il fatto che “non sia riuscita a rilevare la violazione entro le 72 ore previste dalla legge“. Secondo i calcoli della Reuters, la multa ammonta all’1,4% del fatturato di Coupang, pari a 45.000 miliardi di won nel 2025. Mancanza di misure di sicurezza Song Kyung-hee, Presidente dell’autorità di regolamentazione della privacy ha spiegato: “Questo incidente si è verificato a causa della mancanza di misure e sistemi di sicurezza di Coupang. Non per un attacco hacker criminale sofisticato”. Dopo l’annuncio della sanzione, Coupang si è scusata per aver causato allarmi al pubblico e ai propri clienti. La sanzione ha seguito a un’indagine condotta dal Governo all’inizio di quest’anno, che ha attribuito la responsabilità della violazione a una mancanza di attenzione della dirigenza. La misura dell’attacco cyber contro Coupang Proprio per questo, il data breach contro la piattaforma commerciale sudcoreana ha destato non poche preoccupazioni, soprattutto per la sua gestione. L’azienda aveva confermato pubblicamente di aver subìto un attacco cyber su vasta scala. L’operazione si era tradotta nella pubblicazione dei dati personali di oltre 33 milioni di clienti. A rendere ancora più grave il fatto, dalle indagini della Polizia era emerso che la violazione dei server sarebbe cominciata il precedente 24 giugno. Tuttavia, aveva riportato la Reuters, “l’azienda non è venuta a conoscenza del problema fino al 18 novembre“. “La fiducia dei consumatori in Coupang è stata scossa”, ha affermato Lee Kwang-lim, Direttore esecutivo della Korea Chainstores Association, che rappresenta grandi rivenditori come E-mart e Lotte Mart. Il tutto, a riprova di quanto la mancanza di attenzioni interne, per il comparto cyber, possa tradursi anche in aspetti “più di immagine“. Le vulnerabilità delle Telco in Corea del Sud Da tempo gli esperti cyber si interrogano sulle reali misure di protezione delle Telco nel Paese asiatico. Kang Hoon-sik, capo di gabinetto del presidente sudcoreano Lee Jae Myung, aveva affermato nel merito che i quattro principali incidenti cyber dal 2021 hanno tutti evidenziato le “lacune strutturali”. In particolare “nella protezione dei dati personali in Corea del Sud“. Negli ultimi mesi, la Corea del Sud è stata spesso al centro delle cronache per attacchi interni di hacker criminali. La violazione dei server di Coupang, di fatto, è avvenuta contemporaneamente a quella contro LG Uplus. Ad agosto, poi, il più grande operatore di telefonia mobile del Paese, SK Telecom, aveva ricevuto una multa di 134 miliardi di won (96,53 milioni di dollari) dopo un altro attacco informatico. In quel caso, c’era stata una fuga di dati di quasi 27 milioni di utenti. Più in generale, gli analisti hanno segnalato come tutte queste operazioni abbiano interessato i comparti nevralgici del ‘Sistema Paese’ sudcoreano. Ossia: le telecomunicazioni. Le società di carte di credito. Le startup tecnologiche. Varie agenzie governative. La questione dei sistemi nazionali Oltre le accuse di Seoul contro la Cina e la Corea del Nord, diversi esperti hanno segnalato come i problemi restino fondamentalmente due. Il primo luogo, un sistema di sicurezza informatica che è frammentato e non centralizzato, dunque non unitario. Si è registrata inoltre la carenza di tecnici. Da qui, la moltiplicazione delle opportunità per i cyber criminali, con risposte spesso poco tempestive. Per questo, lo stesso Kang aveva affermato che l’incidente cyber contro Coupang, sarebbe dovuto “essere un’opportunità per migliorare il sistema di risarcimento punitivo“. Nell’occasione, infatti, “la sua applicazione non sarebbe avvenuta in modo tale da impedire una compromissione massiccia dei dati“.
cybersecitalia.itJun 12, 2026extracted
Cyber AI, anche la Corea del Sud potrà accedere a Mythos di Anthropic
Si allarga la lista dei Paesi che potranno accedere al modello di AI di Anthropic. Anche la Corea del Sud, in particolare la Korea Internet & Security Agency (KISA), ha ricevuto l’accesso a Mythos, modello di AI di Anthropic. L’ha confermato il Ministero della Scienza e delle Tecnologie dell’Informazione e della Comunicazione (ICT) sudcoreano. Fondamentale, in questo senso, è stata la partecipazione al programma Project Glasswing insieme ad alcune delle principali aziende sudcoreane. Si tratta di un progetto finalizzato a sfruttare i modelli di AI di frontiera nell’identificazione e nella correzione delle vulnerabilità informatiche. L’obiettivo è quello di rafforzare la sicurezza digitale di organizzazioni pubbliche e private. In un comunicato ufficiale, il Ministero ha dichiarato di aver collaborato in modo continuativo con Anthropic e ha confermato il coinvolgimento di KISA nell’iniziativa. Le aziende protagoniste Le autorità sudcoreane hanno dunque formalizzato alcune indiscrezioni del Financial Times. Secondo il quotidiano, Anthropic avrebbe infatti ampliato l’accesso a Mythos a circa 150 organizzazioni distribuite in oltre 15 Paesi, tra cui la Corea del Sud. Tra le aziende coinvolte nell’espansione figurano Samsung Electronics, SK Hynix e SK Telecom, tre dei maggiori gruppi tecnologici del Paese. Il tema per Seoul è strettamente connesso alla Sicurezza Nazionale. Lo scorso anno la Corea del Sud è stata spesso al centro delle cronache per attacchi interni di hacker criminali. Si segnalano la violazione dei server di Coupang, nota azienda di e-commerce e di quelli di LG Uplus. Ad agosto, poi, il più grande operatore di telefonia mobile del Paese, SK Telecom, aveva ricevuto una multa di 134 miliardi di won (96,53 milioni di dollari) dopo un altro attacco informatico. In quel caso, c’era stata una fuga di dati di quasi 27 milioni di utenti. L’apporto e il valore aggiunto dell’AI, dunque, saranno fondamentali per contrastare le minacce e le vulnerabilità. Mythos, per esempio, riesce a individuare falle complesse in tempi molto più rapidi rispetto ai normali gruppi di lavoro. Continuano gli investimenti in materia Lo stesso Ministero ha ribadito che la Corea del Sud continuerà a investire nel rafforzamento delle proprie capacità di cybersicurezza. Tanto attraverso l’utilizzo di diversi modelli avanzati di intelligenza artificiale, quanto nel potenziamento delle tecnologie nazionali di sicurezza informatica basate sull’AI. L’iniziativa rappresenta “un ulteriore passo nella strategia del Paese per consolidare la propria resilienza digitale“. Potrà così mantenere “una posizione di vertice nell’adozione delle tecnologie emergenti applicate alla sicurezza informatica“.
cybersecitalia.itJun 4, 2026extracted
Il Parlamento Europeo si sgancia da Google, al suo posto il francese Qwant
La misure s’inserisce nella volontà delle autorità dell’Unione Europea di costruire una maggiore autonomia digitale dagli Usa. “Da giovedì 4 giugno Qwant sostituirà Google come motore di ricerca predefinito sui computer del Parlamento Europeo“. Lo riporta POLITICO. “Il cambiamento è in linea con l’impegno del Parlamento a favore della sovranità digitale e della protezione dei dati personali degli utenti“. Bruxelles, come del resto la Francia, stanno in questo senso portando avanti una politica simile per una maggiore autonomia digitale dai software statunitensi. Ed in questo senso si può inquadrare l’accordo. Fondata nel 2013, Qwant si è sempre definita come “l’alternativa europea a Google in nome della privacy“. Secondo l’Unione Europea, questo motore europeo è “focalizzato sulla privacy”. La sua progettazione è avvenuta per evitare tracciamento o la raccolta dei dati personali degli utenti. Una volontà condivisa La mossa, sottolinea sempre POLITICO, “fa seguito a mesi di pressioni da parte dei legislatori per ridurre la dipendenza delle istituzioni dell’UE dalla tecnologia americana“. In tal senso, lo scorso anno 38 europarlamentari hanno inviato una lettera al Presidente Roberta Metsola, chiedendo proprio l’abbandono delle tecnologie “made in Usa” a favore di quelle europee. Dal punto di vista operativo i legislatori manterranno la libertà di utilizzare motori di ricerca concorrenti o di modificare le loro impostazioni predefinite. In effetti, le ricerche sul web tramite la barra degli indirizzi nei browser Firefox ed Edge saranno automaticamente indirizzate a Qwant. Non soltanto un tema di browser Oltre al browser, gli interessi dell’Unione sono anche sui sistemi operativi, con particolare riferimento a Microsoft. In più, “i 38 legislatori hanno elencato anche gli schermi, le tastiere e i mouse di Dell, HP e LG. Sono tutti in uso nei sistemi informatici della camera, come tecnologie da abbandonare“. Secondo i rappresentanti del Parlamento, il dominio dei giganti tecnologici statunitensi non serve più ad avere costi efficienti, ma è ormai un rischio per la sicurezza e la prosperità dell’Europa. Il tutto, mentre l’Amministrazione Usa ha rinnovato le richieste di concessioni digitali a più riprese.
cybersecitalia.itJun 3, 2026extracted
Smart TV e tracciamento dei dati: il ruolo delle VPN nella tutela della privacy domestica
All’interno del perimetro della rete domestica, oggi sempre più interconnessa con le infrastrutture aziendali grazie anche allo smart working, la Smart TV rappresenta uno dei vettori di tracciamento e una delle potenziali superfici di attacco meno monitorate. In questo scenario, l’adozione di soluzioni VPN, Virtual Private Network, non risponde più soltanto a logiche di intrattenimento o di sblocco geografico dei cataloghi di streaming, ma si configura come una contromisura architetturale necessaria per la limitazione del data harvesting e la protezione dell’integrità del traffico di rete. Indice degli argomenti Dal punto di vista della sicurezza informatica, la Smart TV costituisce un elemento di criticità sistemica per tre fattori principali: Ciclo di vita delle patch ridotto: a differenza di sistemi operativi per PC o smartphone, i firmware delle Smart TV ricevono aggiornamenti di sicurezza per un lasso di tempo limitato. Dispositivi commercializzati solo pochi anni fa si trovano oggi privi di difese contro vulnerabilità note. Assenza di strumenti di endpoint protection: non è possibile installare agenti di sicurezza (EDR/antivirus) tradizionali sul sistema operativo di una TV, rendendo difficile il rilevamento di eventuali anomalie nel traffico o compromissioni software. Lateral movement (movimento laterale): in una rete non segmentata, la compromissione della Smart TV offre agli attori malevoli una testa di ponte ideale per condurre scansioni della LAN e tentare l’esfiltrazione di dati da dispositivi critici adiacenti, come i laptop aziendali utilizzati in regime di lavoro agile. L’efficacia di una Virtual Private Network applicata a un ecosistema Smart TV non si misura sulla base dell’estetica dell’interfaccia utente, ma dipende da vincoli architetturali ben precisi: Efficienza computazionale del protocollo: i SoC (System on Chip) integrati nei televisori sono ottimizzati per la decodifica video hardware, non per processi di crittografia intensivi. L’utilizzo di protocolli obsoleti o pesanti (come OpenVPN con cifratura AES-256-CBC) può causare vistosi colli di bottiglia, surriscaldamento del chip e conseguente degradazione del frame rate. È fondamentale orientarsi verso soluzioni che supportino implementazioni basate su WireGuard o protocolli proprietari leggeri basati su cifratura ChaCha20. Modalità di deployment (Native App vs. Router-level): la frammentazione dei sistemi operativi rappresenta il principale ostacolo. Android TV (Sony, Philips) e la più recente Apple TV (da tvOS 17) offrono supporto nativo alle applicazioni VPN. Al contrario, sistemi proprietari diffusi come Tizen (Samsung) o webOS (LG) non permettono l’installazione diretta di client. In questi scenari, la protezione deve essere delegata a monte, configurando la VPN direttamente sul router della LAN o sfruttando soluzioni Smart DNS (sebbene queste ultime offrano solo l’offuscamento geografico e non la cifratura del traffico). 🌍 Server: 8.000+ server in 129 paesi 📱 Massimo dispositivi: 10 📍 IP dedicato: ✔ 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: IKEv2/IPsec, OpenVPN, NordLynx 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Panama 🔥 Offerte attive: SCONTO fino al 74% NordVPN si distingue per lo sviluppo di NordLynx, un protocollo proprietario basato sul codice sorgente di WireGuard. NordLynx risolve il limite nativo di WireGuard relativo all’assegnazione degli IP statici introducendo un sistema di Network Address Translation (NAT) doppio e dinamico. Questo garantisce che nessun dato identificativo dell’utente venga memorizzato sul server, coniugando un throughput elevato (essenziale per flussi UHD/4K) a una rigorosa architettura zero-logs. Sotto il profilo della sicurezza perimetrale, l’applicazione integra la funzionalità Threat Protection Pro operante a livello di rete. Questa agisce come un filtro DNS avanzato, intercettando e bloccando le richieste verso domini noti per il phishing, i malware IoT e i tracker pubblicitari legati ai sistemi di ACR degli OEM. L’intera infrastruttura di NordVPN poggia su server RAM-only (diskless), il che significa che il sistema operativo e tutti i dati temporanei risiedono esclusivamente nella memoria volatile, azzerandosi a ogni ciclo di alimentazione o in caso di intrusioni fisiche nei data center. La conformità delle politiche di non-registrazione è regolarmente verificata tramite audit indipendenti condotti da enti terzi come Deloitte. NordVPN propone tre piani d’abbonamento: Base, Plus, Ultimate distribuiti su tre cicli di fatturazione differenti. 2 anni, 1 anno, 1 mese. Rappresenta l’opzione ideale se i servizi di sicurezza perimetrale e di gestione dell’identità sono già delegati ad agent o appliance di terze parti all’interno della LAN. Include l’accesso completo alla rete globale di oltre 9.400 server RAM-only, il protocollo NordLynx, la protezione DNS standard, il monitoraggio base del dark web (Dark Web Monitor™ fino a 5 email) e la copertura di 10 dispositivi simultanei. Opzione 2 anni, sconto 74%): 2,99 €/mese, fatturazione anticipata di 71,76 € per i primi 24 mesi; rinnovo successivo a 139,08 €/anno. Opzione 1 anno, sconto 61%: 4,49 €/mese, fatturazione anticipata di 53,88 € per i primi 12 mesi; rinnovo successivo a 139,08 €/anno. Opzione mensile, sconto 0%: 11,59 €/mese, fatturazione flat ricorrente senza vincoli). Questo livello introduce moduli attivi sul traffico dati, configurandosi come una soluzione ottimale per proteggere la Smart TV e gli altri endpoint dai tentativi di tracciamento e inoculazione di codice malevolo. Aggiunge infatti la suite Threat Protection Pro™ (protezione anti-malware basata su intelligenza artificiale, blocco avanzato di ad e tracker pubblicitari, protezione email illimitata) e include il Password Manager multipiattaforma (NordPass) con annesso Data Breach Scanner. Opzione 2 anni, sconto 76%: 3,49 €/mese, fatturazione anticipata di 83,76 € per i primi 24 mesi; rinnovo a 179,88 €/anno. Opzione 1 anno, sconto 67%: 4,89 €/mese, fatturazione anticipata di 58,68 € per i primi 12 mesi; rinnovo a 179,88 €/anno. Opzione mensile, sconto 0%: 13,69 €/mese. Progettato per una mitigazione del rischio a 360 gradi, il piano Ultimate estende la protezione oltre il perimetro informatico rigido, introducendo tutele legali e finanziarie. Include lo strumento Dark Web Monitor Pro™ (esteso a 8 indirizzi email, numeri di telefono, carte di credito e documenti d’identità), un modulo per il rilevamento delle truffe telefoniche e dello spam (con ID chiamante integrato per Android), 1 TB di spazio di archiviazione cloud crittografata (NordLocker) e un servizio per la rimozione dei dati personali dai registri dei data broker (Incogni). L’elemento di maggiore novità per i professionisti del settore è l’integrazione di un’Assicurazione Cyber dedicata (disponibile nativamente per i residenti in Italia): Copertura Finanziaria Corporate/Consumer: Il pacchetto assicurativo prevede un massimale di copertura fino a 5.000 € destinato al recupero delle perdite finanziarie derivanti da truffe informatiche e al rimborso dei costi legali e amministrativi sostenuti a seguito di un furto d’identità accertato. Opzione 2 anni, sconto 71%: 6,19 €/mese, fatturazione anticipata di 148,56 € per i primi 24 mesi; rinnovo a 256,68 €/anno. Opzione 1 anno, sconto 64%): 7,59 €/mese, fatturazione anticipata di 91,08 € per i primi 12 mesi; rinnovo a 256,68 €/anno. Opzione mensile, sconto 0%): 19,39 €/mese. Tutti i piani mantengono intatte le clausole di salvaguardia finanziaria della garanzia di rimborso entro 30 giorni dall’acquisto iniziale. Qualora l’esito dei test di compatibilità e throughput sulla Smart TV o sul router non soddisfacesse i requisiti minimi di targa della LAN, l’utente può recedere con restituzione integrale del capitale anticipato tramite l’assistenza clienti attiva 24/7. 🌍 Server: 4500+ in 100 paesi 📱 Massimo dispositivi: illimitati 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: OpenVPN, IKEv2, Shadowsocks, Wireguard e L2TP 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Paesi Bassi 🔥 Offerte attive: SCONTO fino all’88% + 3 mesi gratis 🔥 Surfshark adotta un modello di offerta modulare ripartito su tre livelli di servizio, studiati per integrare funzioni di protezione dell’identità e rimozione dei dati personali: Surfshark Starter: comprende i moduli core della VPN, il sistema di mascheramento della geolocalizzazione, il generatore di proxy email e dati sintetici Alternative ID (essenziale per prevenire il tracciamento dei database di profilazione degli OEM) e la suite CleanWeb per il blocco di annunci, tracker, pop-up per il consenso dei cookie e attacchi di phishing a livello DNS. Surfshark One: integra lo stack Starter con un sistema Antivirus completo operante in tempo reale (incluso il monitoraggio delle scansioni pianificate e la protezione della webcam), il motore di ricerca privato Surfshark Search (esente da tracing pubblicitario) e la piattaforma Alert per il monitoraggio in tempo reale dei data leak relativi a email, carte di credito e documenti d’identità. Surfshark One+: rappresenta il livello di massima protezione dell’identità digitale, integrando nativamente l’accesso completo a Incogni. Questo servizio gestisce in modo automatizzato le istanze legali per la rimozione dei dati personali dell’utente dai database dei data broker e dai siti di ricerca di persone, agendo direttamente alla radice della filiera del data harvesting. La sostenibilità economica di Surfshark è legata alle forti economie di scala dei contratti a lungo termine. Rappresenta l’opzione a più alto ROI, con tassi di sconto che raggiungono l’87% grazie all’inclusione di tre mensilità omaggio nel primo periodo di fatturazione (27 mesi totali). VPN Surfshark Starter (Sconto 87%): 1,99 €/mese (Fatturazione anticipata una tantum di 53,73 € per i primi 27 mesi; al termine del periodo promozionale la fatturazione diventa annuale). VPN Surfshark One (Sconto 87%): 2,29 €/mese (Fatturazione anticipata di 61,83 € per i primi 27 mesi). VPN Surfshark One+ (Sconto 80%): 4,19 €/mese (Fatturazione anticipata di 113,13 € per i primi 27 mesi). Configura una soluzione intermedia per l’allocazione del budget a breve termine, applicando lo sconto su un totale iniziale di 15 mesi di servizio. VPN Surfshark Starter, sconto 79%): 3,19 €/mese, fatturazione anticipata di 47,85 € per i primi 15 mesi). VPN Surfshark One, sconto 81%): 3,39 €/mese, fatturazione anticipata di 50,85 € per i primi 15 mesi). VPN Surfshark One+, sconto 66%): 6,99 €/mese, fatturazione anticipata di 104,85 € per i primi 15 mesi). Opzione flat utile esclusivamente per finalità di testing o auditing transitorio della rete, priva di sconti commerciali. VPN Surfshark Starter, sconto 0%): 15,45 €/mese, addebito mensile ricorrente. VPN Surfshark One, sconto 0%): 17,95 €/mese. VPN Surfshark, One+, conto 0%: 20,85 €/mese. Tutti i piani includono una garanzia di rimborso entro 30 giorni dall’acquisto iniziale, offrendo una finestra di recesso completo qualora l’efficienza dei protocolli di tunneling (WireGuard o OpenVPN) non si dimostrasse idonea alle metriche della Smart TV o del gateway perimetrale della LAN. Per gli amministratori di sistema, la piattaforma offre inoltre la possibilità di integrare un modulo per l’IP Dedicato (disponibile su 20 località geografiche) per bypassare i controlli CAPTCHA ed evitare fenomeni di IP blacklisting legati all’uso di indirizzi condivisi. 🇮🇹 Posizioni server in Italia: Milano e Palermo 🌍 Server: 20.017 in 145 Paesi 📱 Massimo dispositivi: 10 🆓 Versione Free: ✔ 💻 Compatibilità: Phone, Android, Mac, Windows, Linux, Fire TV Stick, Chromebook, Android TV, Apple TV 🔐 Sicurezza: Crittografia AES-256 con supporto a WireGuard e OpenVPN 👨💻 Assistenza 24/7: e-mail e ticket (risposta entro 24 ore) 🏢 Sede legale: Svizzera 🔥 Offerte attive: SCONTO fino al 70% Il posizionamento di Proton VPN si distingue per un approccio radicale alla trasparenza architetturale e alla conformità legale. Sviluppato da Proton AG (la tech company svizzera fondata dagli scienziati del CERN nota per ProtonMail), il servizio poggia su fondamenta ingegneristiche e di governance uniche rispetto ai concorrenti di proprietà di grandi conglomerati della sicurezza (come Kape o Nord Security): Codice 100% open source con audit pubblico: a differenza dei modelli closed source, la totalità delle applicazioni di Proton VPN è liberamente ispezionabile dal punto di vista del codice sorgente e viene sottoposta a rigorosi audit periodici eseguiti da laboratori di sicurezza terzi indipendenti (es. Securitum). Trasparenza No-Log validata: la politica di non-registrazione dei log non è una semplice dichiarazione commerciale, ma un’impostazione strutturale pubblicata apertamente, che certifica l’impossibilità di archiviare tabelle di routing, timestamp di sessione o payload dei singoli pacchetti. Giurisdizione elvetica Extra-UE: avendo sede legale in Svizzera, Proton opera al di fuori dei trattati internazionali di intelligence (quali le alleanze 5/9/14 Eyes). Le richieste di esfiltrazione di dati da parte di autorità estere non hanno valore legale diretto se non convalidate da un ordine restrittivo della Corte Federale Svizzera, in un contesto normativo ad altissima tutela della privacy. Per compensare il sovraccarico di rete generato dai protocolli di cifratura avanzati (AES-256 e ChaCha20), Proton ha ingegnerizzato la tecnologia VPN Accelerator. Questo framework ottimizza l’instradamento dei pacchetti superando le limitazioni intrinseche del codice dei server Linux e potenziando il throughput fino al 400% sui collegamenti a lunga distanza. Per una Smart TV, ciò si traduce nella garanzia di flussi ad alta velocità esenti da fenomeni di buffer o instabilità del jitter. Il controllo perimetrale dei dati a livello di trasporto è demandato a NetShield, un modulo integrato che combina un ad-blocker nativo a un sistema di blocco malware basato su liste di reputazione DNS. NetShield agisce a monte dell’endpoint, impedendo alla Smart TV di avviare connessioni outbound verso domini dannosi o server di tracciamento pubblicitario legati ai protocolli ACR. La struttura d’offerta di Proton VPN si concentra su un unico abbonamento premium denominato Proton VPN Plus, che sblocca l’accesso all’intero ecosistema di oltre 20.000 server distribuiti in 140 paesi. Il servizio supporta la protezione simultanea di 10 dispositivi, l’utilizzo di server DNS personalizzati, la compatibilità nativa per Smart TV (Android TV, tvOS, Firestick) e router, oltre a funzionalità avanzate come lo Split Tunneling, le connessioni LAN e il Double Hop (instradamento concatenato multi-server per la massima resilienza all’analisi del traffico). Rappresenta il punto di massima efficienza finanziaria con una riduzione del prezzo di listino pari al 70%. Costo mensile equivalente: 2,99 €/mese Schema di fatturazione: addebito anticipato una tantum di 71,76 € per i primi 24 mesi. Al termine del primo biennio promozionale, il servizio si rinnova automaticamente a una tariffa standard di 83,88 € ogni 12 mesi (pari a 6,99 €/mese). Il risparmio netto sul primo ciclo è di 168 €. Applica una contrazione dei costi operativi pari al 60%, utile per allocazioni di budget a breve termine o test infrastrutturali prolungati. Costo mensile: 3,99 €/mese Schema di fatturazione: addebito anticipato di 47,88 € per i primi 12 mesi. I successivi rinnovi mantengono la tariffa flat di 83,88 € ogni 12 mesi. Il risparmio iniziale sul listino è di 72 €. Opzione pensata esclusivamente per attività di proof-of-concept, auditing temporaneo o analisi forense di rete all’interno della LAN. Costo mensile: 9,99 €/mese Schema di fatturazione: Addebito ricorrente mensile di 9,99 €, privo di sconti o ammortamenti temporali. Tutte le formule di abbonamento beneficiano della garanzia di rimborso entro 30 giorni dall’attivazione. Questo approccio di vendita risk-free consente ai progettisti di rete di implementare Proton VPN sul proprio gateway domestico o aziendale, testare il comportamento dei SoC delle Smart TV sotto crittografia simmetrica e procedere all’eventuale recesso con storno integrale della transazione qualora i KPI prestazionali non risultassero allineati agli standard richiesti. ⚙️ Numero di server: 3.000+ 🌍 Aree geografiche: 160 🗺️ Paesi: 105 📍 IP dedicato: ❌ 📱 Device massimi supportati: fino a 5 dispositivi 🔐 Sicurezza: OpenVPN, IKEv2, Lightway 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Isole Vergini Britanniche 🔥 Offerte attive: SCONTO fino al 49% L’infrastruttura di ExpressVPN si colloca sulla fascia premium del mercato, giustificata da un’evoluzione ingegneristica orientata alla resilienza contro le minacce future e alla massima ottimizzazione del throughput. La suite si sviluppa su tre pilastri tecnologici proprietari: Protezione post-quantistica: ExpressVPN integra nativamente algoritmi di crittografia post-quantistica all’interno del proprio tunnel. Questa architettura difende il traffico dati dagli attacchi di tipo Harvest Now, Decrypt Later (immagazzinamento odierno del traffico cifrato da parte di attori statali o malevoli, volto alla decifrazione futura tramite computer quantistici). Protocollo Lightway (Core in Rust): abbandonando le implementazioni standard, ExpressVPN ha sviluppato Lightway, un protocollo open source con core interamente riscritto in Rust. Questa scelta ingegneristica azzera i difetti di memory-safety tipici del C, riduce le linee di codice per facilitare gli audit e garantisce una velocità di commutazione dei server quasi istantanea, ideale per flussi streaming 4K stabili su Smart TV. Tecnologia TrustedServer: la rete si estende su 105 paesi e opera esclusivamente su server basati su memoria RAM volatile. Poiché i nodi non scrivono mai su disco rigido, l’intero stack software e i dati di transito vengono completamente polverizzati a ogni ciclo di riavvio elettrico, garantendo l’applicazione fisica della politica di zero-log. La suite integra il sistema Threat Manager, che opera a livello di gateway bloccando preventivamente i tracker, i domini di phishing e i siti per adulti. Per i dispositivi sprovvisti di supporto nativo alle VPN, ExpressVPN include il servizio DNS MediaStreamer, utile per lo sblocco geografico rapido senza l’overhead della crittografia. I piani superiori estendono la protezione oltre il perimetro di rete tramite ExpressKeys (gestore di password con report sulla vulnerabilità delle credenziali), ExpressMailGuard (generatore di alias email anonimi) ed ExpressAI (assistente IA privato). A partire dal 2026, l’offerta commerciale di ExpressVPN abbandona la tariffazione a SKU singola per strutturarsi su tre differenti tier di servizio: Base, Avanzato, Pro, distribuiti su tre cicli di fatturazione. Rappresenta l’opzione a più alto ROI per l’ammortamento dei costi fissi, estendendo la copertura iniziale a 28 mesi totali. ExpressVPN Base (cconto 80%): 2,29 €/mese. Addebito anticipato una tantum di 64,12 € per i primi 28 mesi. Successivamente si rinnova a 79,95 €/anno. Include 10 connessioni simultanee e protezione di rete Lite. Risparmio totale: 257,60 €. ExpressVPN Avanzato (sconto 76%): 2,99 €/mese. Addebito anticipato di 83,72 € per i primi 28 mesi. Successivamente si rinnova a 109,95 €/anno. Eleva i dispositivi a 12, sblocca ExpressKeys, 100 alias email e piani eSIM inclusi (holiday.com). Risparmio totale: 266,00 €. ExpressVPN Pro (sconto 71%): 4,99 €/mese. Addebito anticipato di 139,72 € per i primi 28 mesi. Successivamente si rinnova a 179,95 €/anno. Supporta 14 dispositivi, IP Dedicato incluso, alias email illimitati ed ExpressAI (500 crediti/giorno). Risparmio totale: 350,00 €. ExpressVPN: 12 mesi + 3 mesi extra: caratteristiche tecniche e costi Soluzione intermedia focalizzata sulla flessibilità di budget, con copertura iniziale riscaldata su 15 mesi totali. ExpressVPN Base, sconto 69%): 3,49 €/mese, fatturazione anticipata di 52,35 € per i primi 15 mesi; rinnovo a 79,95 €/anno. Risparmio: 120,00 €. ExpressVPN Avanzato, sconto 64%): 4,49 €/mese, fatturazione anticipata di 67,35 € per i primi 15 mesi; rinnovo a 109,95 €/anno. Risparmio: 120,00 €. ExpressVPN Pro, sconto 62%): 6,49 €/mese, fatturazione anticipata di 97,35 € per i primi 15 mesi; rinnovo a 179,95 €/anno. Risparmio: 165,00 €. Profilo flat privo di sconti o agevolazioni temporali, consigliato esclusivamente per attività di auditing e test prestazionali. ExpressVPN Base: 11,49 €/mese, rinnovi automatici mensili ricorsivi. ExpressVPN Avanzato: 12,49 €/mese. ExpressVPN Pro: 17,49 €/mese, include IP dedicato e moduli IA. Tutti i contratti attivati prevedono una garanzia di rimborso entro 30 giorni dedicata ai nuovi utenti. In caso di performance non allineate ai flussi UHD o di incompatibilità con i router della LAN, il recesso consente lo storno completo dei canali di pagamento utilizzati. L’integrazione di una Smart TV all’interno di un’infrastruttura di rete domestica o aziendale introduce vettori di vulnerabilità legati al tracciamento dei dati (tecnologie ACR – Automatic Content Recognition) e alla potenziale esfiltrazione di informazioni sensibili da parte di firmware IoT scarsamente aggiornati. Per mitigare questi rischi e massimizzare le prestazioni dei flussi streaming in 4K, l’approccio ingegnerisico richiede la separazione logica del traffico e la centralizzazione della VPN a livello di perimetro. La prima linea di difesa per la messa in sicurezza della LAN prevede la creazione di una VLAN dedicata ai dispositivi IoT e Smart TV (es. VLAN 20), mantenendo i dispositivi di produzione (PC, NAS, smartphone) isolati sulla rete principale (VLAN 10). Isolamento del traffico (Layer 2): configurando regole di firewall sul router/gateway perimetrale, si deve interdire qualsiasi comunicazione cross-VLAN originata dalla VLAN 20 verso la VLAN 10. La Smart TV deve poter stabilire esclusivamente connessioni outbound verso l’esterno (Internet) e rispondere solo a sessioni autorizzate provenienti dalla rete protetta (es. per il mirroring locale). Mitigazione del Broadcast: isolare la Smart TV in una subnet dedicata riduce il rumore di broadcast della rete principale, ottimizzando le risorse di calcolo del SoC (System on Chip) del televisore, spesso limitato sul piano hardware. [INTERNET] ──> [Gateway / Firewall] │ ├─> [VLAN 10: Produzione] ──> PC / NAS / Smartphone (Dati Protetti) │ └─> [VLAN 20: IoT/Smart TV] ──> Centralizzazione VPN (No Accesso a VLAN 10) Sebbene i principali provider analizzati, NordVPN, Surfshark, Proton VPN, ExpressVPN, offrano applicazioni native per Android TV, tvOS Apple TV e Firestick, la centralizzazione del tunnel sul router perimetrale (o su un router in cascata dedicato come la soluzione ExpressVPN Aircove) rappresenta la scelta architetturale più efficiente per i seguenti motivi: Sgravio computazionale dell’endpoint: la decifratura e cifratura dei pacchetti tramite protocolli complessi (quali WireGuard o Lightway) richiede cicli di CPU intensivi. Demandando questo carico hardware al processore del router, si azzerano i micro-scatti e i problemi di buffering causati dal surriscaldamento del SoC della Smart TV. Protezione dei dispositivi legacy (MediaStreamer e Smart DNS): alcuni sistemi operativi per Smart TV (es. WebOS di LG o Tizen di Samsung) non supportano nativamente l’installazione di client VPN. Operando a livello di router, l’intero traffico della VLAN 20 viene incapsulato nel tunnel in modo trasparente rispetto al sistema operativo dell’endpoint. In alternativa, l’uso di DNS personalizzati (come il MediaStreamer di ExpressVPN o lo Smart DNS di NordVPN) configurati staticamente sulla TV permette lo sblocco geografico senza cifratura, minimizzando l’overhead di rete. Per garantire la continuità dei flussi UHD (Ultra High Definition) ed evitare degradazioni prestazionali dovute alla contemporaneità dei download sulla rete, è necessario implementare politiche di controllo della larghezza di banda: Assegnazione delle priorità (QoS): sul router deve essere impostata una regola di QoS basata sull’indirizzo IP statico o sul MAC Address della Smart TV, classificando il suo traffico come High Priority per i pacchetti multimediali (RTP/RTSP). Ottimizzazione della MTU (Maximum Transmission Unit): l’incapsulamento VPN aggiunge un overhead ai pacchetti IP. Per evitare fenomeni di frammentazione del payload – che causerebbero latenza e buffering nello streaming – è consigliabile ottimizzare il valore di MTU sul router (tipicamente riducendolo a un valore compreso tra 1420 e 1440 byte se si utilizza WireGuard/Lightway, rispetto ai 1500 byte standard delle connessioni WAN). L’adozione combinata di una VLAN isolata e di un tunnel VPN centralizzato sul gateway permette di coniugare le esigenze di sicurezza perimetrale e conformità dei dati con le massime metriche di stabilità e throughput richieste dall’intrattenimento ad altissima definizione.
cybersecurity360.itMay 26, 2026extracted
The hidden smart fridge risks that emerge years after purchase
The hidden smart fridge risks that emerge years after purchase Household refrigerators are built to last more than a decade. The software, cloud services, and mobile apps that control them are not. A new analysis from Erik Buchmann at Leipzig University maps what happens when those two timelines collide, and the findings reach further than the kitchen. The study examines three current models on the market: the Bosch KGN36HI32, the Samsung RF27T5501SG, and the LG GSX960NEAZ. Each adds network connectivity, mobile control, and in some cases cameras, voice assistants, and touchscreen apps to a core appliance whose mechanical components are expected to keep working for over ten years. IT architecture (Source: Research paper) Even basic cooling can depend on the cloud Even cooling can become a long-term risk when the appliance ships with a stripped-down control panel and routes temperature adjustments through a smartphone app and a vendor cloud account. The Samsung RF27T5501SG, for example, requires owners to install the SmartThings app and register for a Samsung cloud account to access many functions. If any link in that chain goes away, a working compressor and a working sensor array may still leave the owner with an appliance they can no longer configure as intended. A parallel case from earlier IoT history saw tens of thousands of internet radios stop working after a service provider shut down. Three families of long-term risk Buchmann groups the risks into compliance, economic, and operational categories. Compliance risks come from changes in law and regulation after purchase. Privacy rules can restrict where personal data flows, trade and sanctions regimes can cut off specific vendors or regions, and product categories can be reclassified entirely. Germany banned a children’s smart toy three years after launch once authorities determined it functioned as a covert listening device. Economic risks track the business decisions of the companies that keep the ecosystem running. Vendors can degrade older services to push customers toward newer products, switch to subscription pricing, discontinue a cloud platform, or go out of business and void existing warranties. Seven of the eight use cases identified in the study depend on services run by parties other than the owner. Operational risks accumulate through technical aging. Devices lose compatibility with newer phones and home networks, security updates stop arriving, and expertise and spare parts for older interfaces become hard to source. Protocols considered secure at purchase can be deprecated within a few years. The security cost of multimedia features Buchmann’s protection-needs analysis produces a finding that has practical consequences for anyone using a fridge as a smart-home hub. Because the appliance handles configuration data, credentials, and operating system updates, every other service it runs inherits the same elevated security requirement. Streaming music or browsing recipes on the door panel is therefore tied to the same protection level as the device’s most sensitive functions. A weakness in a casual feature can expose the rest. Thomas Uhlemann, Cybersecurity Evangelist at AV-Comparatives, told Help Net Security that the problem compounds once vendor updates stop. “As soon as a vendor stops shipping updates, the appliance freezes in time, but the threat landscape around it does not. Outdated TLS implementations, deprecated cipher suites, unpatched Wi-Fi stacks, hard-coded credentials in old firmware: all of these become permanent residents on the same LAN as everything else the household relies on.” In AV-Comparatives’ lab work, Uhlemann says two failure modes recur. “An appliance with a weak or unauthenticated local API, still common in older smart kitchen firmware, gives an attacker who has already gained a foothold elsewhere a stable pivot point. The fridge does not need to be the entry vector to be the problem; it only needs to be reachable.” The second is protocol decay, where a device keeps speaking to its cloud backend over TLS configurations that current browsers would reject, or advertising internal network topology through legacy services. The conclusion from the lab matches the conclusion from the paper. “The security posture of a home network is set by its weakest long-lived device,” Uhlemann says. A well-configured router and current endpoint protection raise the baseline, “but they cannot retroactively fix a device whose manufacturer has walked away from it.” It’s annoying, not catastrophic There’s some good news in here. For a regular household, none of the risks rise to the worst harm category in the analysis, things like serious illness from food poisoning or steep fines. The realistic worst cases are food that spoils, digital features that stop working for good, privacy exposure, and the appliance becoming an expensive paperweight. Buchmann adds that the math changes in higher-stakes settings, like a hospital using a connected fridge to store medication. The lesson extends beyond fridges Any consumer product that pairs long-lived hardware with software dependencies inherits the same structural problem. Smart televisions, connected ovens, networked thermostats, and home security panels all sit on the same fault line. The catalog of risks Buchmann assembles can be applied to any of them with minor adjustments to the asset inventory. Anyone shopping for a smart appliance has a new question to weigh at the store: what will it still do once its supporting ecosystem moves on? Bosch, LG and Samsung did not respond to a request for comment by the time of publication.
helpnetsecurity.comMay 12, 2026extracted
Privacy Platform Cloaked Raises $375M to Expand Enterprise Reach
Consumer privacy and security company Cloaked on Thursday announced raising $375 million in a Series B funding round and growth financing to accelerate its product roadmap and scale its platform for both individual users and businesses. The latest funding, which brings the total raised by the company to more than $400 million, was led by General Catalyst and Liberty City Ventures, with participation from Lux Capital, Human Capital, Marquee Ventures, Fifth Growth Fund, NFL Players Association, LG Technology Ventures, Assurant Ventures, and DuckDuckGo. Cloaked offers a comprehensive privacy platform designed to give individuals control over their personal information across multiple fronts. Its core functionality includes the generation of unlimited, unique virtual identities — such as phone numbers, email addresses, and passwords — that users can employ when signing up for online services, effectively shielding their real contact details from potential exposure. The platform also features an automated data removal tool that continuously scans for and deletes users’ personal information from data brokers and people-search websites. Additionally, its AI-powered Call Guard feature screens incoming calls in real time to block spam, scams, and fraud. The company intends to use the new capital, among other things, to introduce a suite of AI-driven personal agents. These agents are designed to act on behalf of users to monitor, manage, and enforce privacy preferences and security postures across their digital footprint. Alongside its consumer growth, Cloaked is scaling its enterprise offering, Cloaked Enterprise, which was launched late last year. This Digital Workforce Protection program is designed to identify and mitigate cybersecurity risks that originate from employees’ personal digital exposure. “We’ve disguised more than 10 million identities, removed over a billion records from data broker sites, and screened more than 40 million calls – and we’re just getting started,” said Arjun Bhatnagar, co-founder and CEO of Cloaked. “The fight for consumer privacy is at an inflection point with Cloaked building the platform that makes privacy easy to understand, simple to defend, and a mandatory aspect of daily life.” Related: Raven Emerges From Stealth With $20 Million in Funding Related: Autonomous Offensive Security Firm XBOW Raises $120M at $1B+ Valuation Related: Cloud Security Startup Native Exits Stealth With $42 Million in Funding
securityweek.comMar 19, 2026extracted
Attacco cyber contro Coupang, gli effetti della violazione sui ricavi nel quarto trimestre
Gli effetti sul mercato del data breach contro Coupang continuano ad essere prolungati, con direttrici non solo economiche ma anche di immagine. A molti mesi dall’attacco cyber contro Coupang, il gigante dell’e-commerce sudcoreano continua ad avere dei riscontri in proiezione negativi sul mercato. Perdite nel quarto trimestre e ricavi inferiori alle stime degli analisti. Sono queste le evidenti ripercussioni della violazione informatica. Coupang ha infatti riportato una perdita di 26 milioni di dollari nel quarto trimestre, rispetto ai profitti dello stesso periodo dell’anno precedente. Nonostante le difficoltà, la società ha preso una serie di provvedimenti per riprendersi dalla crisi generata dal data breach. La compagnia ha lavorato “per rassicurare i suoi clienti e migliorare la sicurezza dei propri sistemi, con l’intento di mantenere e poi aumentare la base clienti nel lungo termine“. Non sarà facile ma potrà contare su un settore, quello del commercio online, che in Corea del Sud resta altamente competitivo competitivo e in rapida evoluzione. Il tutto, al cospetto di continue sfide digitali e reputazionali. La misura dell’attacco cyber contro Coupang Quello del data breach contro la piattaforma commerciale sudcoreana ha destato non poche preoccupazioni, sopratutto per la sua gestione. Coupang aveva reso noto, circa tre mesi fa, di aver subìto un attacco cyber su vasta scala. L’operazione si era tradotta nella pubblicazione dei dati personali di oltre 33 milioni di clienti. A rendere ancora più grave il fatto, dalle indagini della Polizia era emerso che la violazione dei server sarebbe cominciata il precedente 24 giugno. Tuttavia, aveva riportato la Reuters, “l’azienda non è venuta a conoscenza del problema fino al 18 novembre“. “La fiducia dei consumatori in Coupang è stata scossa”, ha affermato Lee Kwang-lim, Direttore esecutivo della Korea Chainstores Association, che rappresenta grandi rivenditori come E-mart e Lotte Mart. Il tutto, a riprova di quanto la mancanza di attenzioni interne, per il comparto cyber, possa tradursi anche in aspetti “più di immagine“. Le vulnerabilità delle Telco in Corea del Sud Kang Hoon-sik, capo di gabinetto del presidente sudcoreano Lee Jae Myung, aveva affermato nel merito che i quattro principali incidenti cyber dal 2021 hanno tutti evidenziato le “lacune strutturali”. In particolare “nella protezione dei dati personali in Corea del Sud“. Negli ultimi mesi, la Corea del Sud è stata spesso al centro delle cronache per attacchi interni di hacker criminali. La violazione dei server di Coupang, di fatto, è avvenuta contemporaneamente a quella contro LG Uplus. Ad agosto, poi, il più grande operatore di telefonia mobile del Paese, SK Telecom, aveva ricevuto una multa di 134 miliardi di won (96,53 milioni di dollari) dopo un altro attacco informatico. In quel caso, c’era stata una fuga di dati di quasi 27 milioni di utenti. Più in generale, gli analisti hanno segnalato come tutte queste operazioni abbiano interessato i comparti nevralgici del ‘Sistema Paese’ sudcoreano. Ossia: le telecomunicazioni. Le società di carte di credito. Le startup tecnologiche. Varie agenzie governative. La questione dei sistemi nazionali Mentre Seoul continua ad accusare la Cina e la Corea del Nord, diversi esperti hanno segnalato come i problemi restino fondamentalmente due. Il primo luogo, un sistema di sicurezza informatica che è frammentato e non centralizzato, dunque non unitario. Si è registrata inoltre la carenza di tecnici. Da qui, la moltiplicazione delle opportunità per i cyber criminali, con risposte spesso poco tempestive. Per questo, lo stesso Kang aveva affermato che l’incidente cyber contro Coupang, sarebbe dovuta “essere un’opportunità per migliorare il sistema di risarcimento punitivo“. Nell’occasione, infatti, “la sua applicazione non sarebbe avvenuta in modo tale da impedire una compromissione massiccia dei dati“.
cybersecitalia.itMar 3, 2026extracted
Samsung TVs stop spying on viewers in Texas. Here’s how to disable ACR anywhere
Samsung has settled a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). As part of the settlement, Samsung agreed to stop collecting ACR data from Texans without explicit, informed consent and to rewrite its on‑screen privacy prompts and dialogs. Texas Attorney General (AG) Paxton stated: “I commend Samsung for being one of the first smart TV companies in the world to make these important changes.” The Texas AG sued Samsung and other TV makers (Hisense, Sony, LG, TCL) over ACR-based “mass surveillance programs” monitoring what people watch and building profiles used for advertising and monetization. ACR works by: Taking tiny samples of the sound or picture from what’s on your screen (a few seconds at a time). Turning those samples into a kind of fingerprint (a compact pattern that uniquely represents that content). Comparing that fingerprint to a giant database of known shows, movies, channels, and ads to find a match. If it finds a match, the system knows “this TV user is watching Episode X of Show Y at time Z” or “this ad just played on this device.” Paxton argues that customers did not meaningfully consent to this data collection, which he calls “watchware,” framing it as deliberate monitoring, rather than an accident. Samsung also faces a federal class action in New York. Plaintiffs claim Samsung TVs track, store, and sell viewing data to companies such as Google and X (Twitter) without informed consent, in violation of the federal Video Privacy Protection Act and various state privacy laws. The New York complaint further alleges that Samsung’s ACR records image and audio every 500 ms regardless of source (broadcast, streaming apps, or PC monitor use), and that Samsung’s privacy notice downplays the scope of that data collection by referring to “processing” viewing history. How to disable ACR If you’d prefer to limit or disable ACR-style monitoring of your watching behavior, here’s where to look. Menu names may vary slightly depending on the model and year. Samsung Samsung has agreed to modify its consent and disclosure practices for Texas residents as part of the settlement. Users elsewhere can manually adjust these settings: Press Home on the remote. Go to Settings → Support → Terms & Privacy → Privacy Choices (or Settings → All Settings → General & Privacy → Terms & Privacy / Privacy Choices). Turn Viewing Information Services off (this is Samsung’s ACR). Optional hardening: In the same menu area, disable Interest-Based Advertising and any Voice Recognition Services if you don’t want voice data sent off‑box. LG TVs (webOS) Press Settings (gear icon). Go to All Settings → General → System → Additional Settings. Set Live Plus to off (this is LG’s ACR layer). In the same or nearby menu, enable Limit Ad Tracking (or similar option) to reduce ad profiling. Vizio TVs Press Menu on the remote. Go to System → Reset & Admin. Turn Viewing Data off (this disables Vizio’s ACR and viewing logs). Sony TVs (Google TV / Android TV) Many Sony TVs use Samba Interactive TV as the ACR component. Press Home. For newer Google TV models: - Go to Settings → All Settings → Privacy; toggle Samba Interactive TV off. For models using usage‑diagnostics style controls: - Go to Settings → Device Preferences → Usage & Diagnostics and turn all reporting off. This disables the Samba ACR integration and general telemetry used for ad/experience tuning. Roku TVs (TCL, Hisense, etc. running Roku OS) From the Roku home screen, go to Settings → Privacy. Under Advertising: - Uncheck / toggle off Personalize ads (this stops use of your advertising ID for interest‑based ads). - Optionally select Reset advertising ID to rotate the ID. Under Smart TV Experience (if present): - Turn off Use info from TV inputs to stop ACR on HDMI and other external sources. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comMar 2, 2026extracted
Samsung TVs to stop collecting Texans’ data without express consent
Samsung and the State of Texas have reached a settlement agreement over the alleged unlawful collection of content-viewing information through its smart TVs As part of the agreement, the TV manufacturer will revise its privacy disclosures to clearly explain its data collection and processing practices to consumers. Last December, Texas Attorney General Ken Paxton filed a lawsuit against several TV manufacturers, including Samsung, alleging that they use Automated Content Recognition (ACR) technology to collect and process viewing data without first obtaining their express, informed consent. In January, Texas obtained a short-lived temporary restraining order (TRO) against Samsung to stop the unlawful collection of consumer data in the state, confirming a violation of the Texas Deceptive Trade Practices Act (DTPA). Although the order was vacated on the following day, the lawsuit remained active. The allegations against Samsung were that it uses ACR technology to capture screenshots of consumers’ TVs to determine what they’re watching. The South Korean tech giant would use this information for targeted advertising. In support of the TRO, the Court found that there was "good cause to believe" that Samsung automatically enrolled customers in this system using "dark patterns" that included "over 200 clicks spread across four or more menus for a consumer to read the privacy statements and disclosures." In a statement to BleepingComputer, Samsung stated that, while it does not agree that its Viewing Information Services (VIS) system violated any regulations, it has agreed to "make enhancements to further strengthen our privacy disclosures." “While we maintain our original television privacy policy and notices followed existing Texas state regulations, as a trusted brand, Samsung is proud to be at the forefront of protecting consumer privacy and security,” stated a spokesperson of Samsung Electronics America. “The settlement affirms what Samsung has said since this lawsuit was filed - Samsung TVs do not spy on consumers. In fact, Samsung allows you to control your privacy - and change your privacy settings at any time.” “As part of the agreement, Samsung must halt any collection or processing of ACR viewing data without obtaining Texas consumers’ express consent,” announced Texas AG Ken Paxton. “Additionally, it compels Samsung to promptly update its smart TVs and implement disclosures and consent screens that are clear and conspicuous to ensure that Texans can make an informed decision regarding whether their data is collected and how it’s used.” Paxton commended Samsung for agreeing to implement consumer safeguards, while he underlined that others haven’t moved with a similar fervor as of yet. Smart TV manufacturers, including Sony, LG, Hisense, and TCL Technologies, have not made any changes in response to the lawsuits yet. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 1, 2026extracted
Samsung updates ACR privacy practices after Texas sues TV manufacturers
Samsung updates ACR privacy practices after Texas sues TV manufacturers Texas Attorney General Ken Paxton on Thursday said Samsung agreed to stop collecting and processing Automated Content Recognition (ACR) viewing data without first getting consent from Texas consumers, ending a lawsuit filed by the state in December. ACR data captures TV users’ viewing habits in real time, and manufacturers have found profits from selling the information to advertisers and other organizations. Paxton sued five major smart TV manufacturers — Samsung, Sony, LG, Hisense and TCL Technology — for allegedly collecting ACR data without consumers in the state being fully informed and consenting. Samsung is the first company to make changes in response to the lawsuit, and said it will “promptly update” its smart TVs by creating disclosure and consent screens that are “clear and conspicuous to ensure that Texans can make an informed decision regarding whether their data is collected and how it’s used,” the AG’s press release said. A Samsung spokesperson said in a statement that it “shares the Texas Attorney General’s goal of promoting transparent and consumer-friendly privacy practices.” “While we maintain our original television privacy policy and notices followed existing Texas state regulations, as a trusted brand, Samsung is proud to be at the forefront of protecting consumer privacy and security.” The statement added that Samsung TVs “do not spy on customers.” “Samsung allows you to control your privacy – and change your privacy settings at any time,” it said. Lawsuits with the other TV manufacturers are ongoing. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaFeb 27, 2026extracted
Attacco cyber contro Coupang, continuano le valutazioni sugli effetti di mercato
Gli effetti sul mercato del data breach contro Coupang continuano ad essere elemento di dibattito in Corea del Sud. Gli investitori del gigante sudcoreano dell’e-commerce Coupang continuano adesamirare i risultati finanziari sul mercato dell’azienda. Gli effetti del data breach – con oltre 33 milioni di utenti colpiti – continuano a farsi sentire, mentre crescono gli effetti della concorrenza. È ancora in corso un’indagine condotta dal Governo. In un aggiornamento di questo mese il Ministero della Scienza ha attribuito “la responsabilità all’inadempienza della direzione di Coupang e non ad un sofisticato attacco informatico“. L’azienda ha già comunicato che adotterà tutte le misure necessarie per prevenire ulteriori danni e continuerà a rafforzare le misure di sicurezza per evitare il ripetersi di episodi simili. “La fiducia dei consumatori in Coupang è stata scossa”, ha affermato Lee Kwang-lim, Direttore esecutivo della Korea Chainstores Association, che rappresenta grandi rivenditori come E-mart e Lotte Mart. L’attacco cyber contro Coupang Quello del data breach contro la piattaforma commerciale sudcoreana ha destato non poche preoccupazioni, sopratutto per la sua gestione. Coupang aveva reso noto, circa tre mesi fa, di aver subìto un attacco cyber su vasta scala. L’operazione si era tradotta nella pubblicazione dei dati personali di oltre 33 milioni di clienti. A rendere ancora più grave il fatto, dalle indagini della Polizia era emerso che la violazione dei server sarebbe cominciata il precedente 24 giugno. Tuttavia, aveva riportato la Reuters, “l’azienda non è venuta a conoscenza del problema fino al 18 novembre“. Le vulnerabilità delle Telco in Corea del Sud Kang Hoon-sik, capo di gabinetto del presidente sudcoreano Lee Jae Myung, aveva affermato nel merito che i quattro principali incidenti cyber dal 2021 hanno tutti evidenziato le “lacune strutturali”. In particolare “nella protezione dei dati personali in Corea del Sud“. Negli ultimi mesi, la Corea del Sud è stata spesso al centro delle cronache per attacchi interni di hacker criminali. La violazione dei server di Coupang, di fatto, è avvenuta contemporaneamente a quella contro LG Uplus. Ad agosto, poi, il più grande operatore di telefonia mobile del Paese, SK Telecom, aveva ricevuto una multa di 134 miliardi di won (96,53 milioni di dollari) dopo un altro attacco informatico. In quel caso, c’era stata una fuga di dati di quasi 27 milioni di utenti. Più in generale, gli analisti hanno segnalato come tutte queste operazioni abbiano interessato i comparti nevralgici del ‘Sistema Paese’ sudcoreano. Ossia: le telecomunicazioni. Le società di carte di credito. Le startup tecnologiche. Varie agenzie governative. La necessità di un miglioramento dei sistemi nazionali Mentre Seoul continua ad accusare la Cina e la Corea del Nord, diversi esperti hanno segnalato come i problemi restino fondamentalmente due. Il primo luogo, un sistema di sicurezza informatica che è frammentato e non centralizzato, dunque non unitario. Si è registrata inoltre la carenza di tecnici. Da qui, la moltiplicazione delle opportunità per i cyber criminali, con risposte spesso poco tempestive. Per questo, lo stesso Kang aveva affermato che l’incidente cyber contro Coupang, sarebbe dovuta “essere un’opportunità per migliorare il sistema di risarcimento punitivo“. Nell’occasione, infatti, “la sua applicazione non sarebbe avvenuta in modo tale da impedire una compromissione massiccia dei dati“.
cybersecitalia.itFeb 26, 2026extracted
Texas sues TP-Link over Chinese hacking risks, user deception
Texas sued networking giant TP-Link Systems, accusing the company of deceptively marketing its routers as secure while allowing Chinese state-backed hackers to exploit firmware vulnerabilities and access users' devices. The lawsuit follows an investigation launched in October and claims that TP-Link misled buyers by labeling its products "Made in Vietnam" while sourcing nearly all components from China. According to Texas Attorney General Paxton, this is important because Chinese law can compel companies with Chinese supply-chain ties to cooperate with government intelligence requests and hand over user data. "This week, my office is launching a coordinated series of actions against CCP-aligned companies to send a clear message that in the Lone Star State we will always put Texas and America First," said Paxton. "TP Link will face the full force of the law for putting Americans' security at risk. Let this serve as a clear warning to any Chinese entity seeking to compromise our nation's security." The suit points to a history of security failures, including firmware vulnerabilities exploited by Chinese hacking groups and the company's routers being used in a large-scale credential-theft botnet later linked to password-spray attacks. As Microsoft reported in October 2024, this botnet (tracked as Quad7, CovertNetwork-1658, or xlogin) was built from hacked home and small-business routers (primarily TP-Link devices) and operated by Chinese threat actors. "Despite its claims of privacy and security, TP Link's products have been used by People's Republic of China's ("PRC") state-sponsored hacking entities to launch multiple cyber-attack operations against the United States," Paxton added. "With nearly all of its products' parts imported from China, TP Link's deliberate deception towards Texans regarding the nationality, privacy, and security capabilities of its networking devices is not just illegal—it is also a national security threat that enables the secret surveillance and exploitation of Texas consumers." Paxton now seeks civil monetary penalties and injunctions that would require TP-Link to disclose the Chinese origins of its devices and stop collecting consumer data without informed consent. Federal agencies have previously flagged actively exploited flaws in TP-Link hardware, and CISA currently lists half a dozen TP-Link security flaws in its catalog of vulnerabilities known to be exploited in attacks. In December 2024, the U.S. government was also reportedly considering banning TP-Link routers, with the U.S. Departments of Justice, Commerce, and Defense investigating the issue, and at least one Commerce Department office having subpoenaed the company. More recently, in December 2025, the Texas Attorney General sued five major television manufacturers (i.e., Sony, Samsung, LG, and China-based companies Hisense and TCL Technology Group Corporation), accusing them of secretly and illegally collecting their users' data using Automated Content Recognition (ACR) technology. A TP-Link spokesperson told BleepingComputer today that Texas Attorney General Paxton's allegations are "without merit and will be proven false," that neither the Chinese government nor the Chinese Communist Party (CCP) exercises control over the company, its products, or user data, and added that all U.S. user data is stored on Amazon Web Services servers. "TP-Link Systems Inc. is an independent American company. Neither the Chinese government nor the CCP exercises any form of ownership or control over TP-Link, its products, or its user data. TP-Link’s founder and CEO, Jeffrey Chao, resides in Irvine, CA, and is not and never has been a member of the CCP," the spokesperson said. "To ensure the highest level of security, our core operations and infrastructure are located entirely within the United States, and all U.S. users' networking data is stored securely on Amazon Web Services servers. We will continue to vigorously defend our reputation as a trusted provider of secure connectivity for American families." Update February 19, 11:19 EST: Added TP-Link statement. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comFeb 19, 2026extracted
Hobby coder accidentally creates vacuum robot army
Sammy Azdoufal wanted to steer his robot vacuum with a PS5 controller. Like any good maker, he thought it would be fun to drive a new DJI Romo around manually. He ended up gaining access to an army of robotic cleaners that gave him eyes into thousands of homes. Driven by purely playful reasons, Azdoufal used Anthropic’s Claude Code AI coding assistant to reverse-engineer his Romo’s communication protocols. But when his homebrew app connected to DJI’s servers, roughly 7,000 robot vacuums across 24 countries started answering. He could watch their live camera feeds, listen through onboard microphones, and generate floor plans of homes he’d never visited. With just a 14-digit serial number, he pinpointed a Verge journalist’s robot, confirmed it was cleaning the living room at 80% battery, and produced an accurate map of the house from another country. The technical failure was almost comically basic. DJI’s MQTT message broker had no topic-level access controls. Once you authenticated with a single device token, you could see traffic from others device in plaintext. It wasn’t only vacuums that answered back. DJI’s Power portable battery stations, which run on the same MQTT infrastructure, also showed up. These are home-backup generators expandable to 22.5kWh, marketed for keeping your house running during outages. What makes this different from a conventional security discovery is how it happened. Azdoufal used Claude Code to decompile DJI’s mobile app, understand its protocol, extract his own authentication token, and build a custom client. AI coding tools are lowering the bar for advanced offensive security. The population capable of probing Internet of Things (IoT) protocols just got much, much larger, further eroding any remaining faith in security through obscurity. Why plenty of IoT vacuum cleaners suck This isn’t the first time someone has remotely pwned a robot vacuum cleaner. In 2024, hackers commandeered Ecovacs Deebot X2 vacuums across US cities, shouting slurs through speakers and chasing pets around. Ecovacs’s PIN protection was checked only by the app, never by the server or the device. Last September, South Korea’s consumer watchdog tested six brands. While Samsung and LG fared well, and found serious flaws in three Chinese models. Dreame’s X50 Ultra allowed remote camera activation. Researcher who Dennis Giese later reported a TLS vulnerability in Dreame’s app to CISA. Dreame didn’t respond to CISA’s queries. The pattern keeps repeating: manufacturers ship vacuums with textbook security failures, ignore researchers, then scramble when journalists publish. DJI’s initial response made things worse. Spokesperson Daisy Kong told The Verge the flaw had been fixed the prior week. That statement arrived about thirty minutes before Azdoufal demonstrated thousands of robots, including the journalist’s own review unit, still reporting in live. DJI later issued a fuller statement acknowledging a backend permission validation issue and two patches, on February 8 and 10. DJI said that TLS encryption was always in place, but Azdoufal says that protects the connection, not what’s inside it. He also told The Verge that additional vulnerabilities remain unpatched, including a PIN bypass on the camera feed. Regulators are applying pressure Regulation is arriving, slowly. The EU’s Cyber Resilience Act will require mandatory security-by-design for all connected products sold in the bloc by December 2027, with fines up to €15 million. The UK’s PSTI Act, in force since April 2024, became the world’s first law banning default passwords on smart devices. The US Cyber Trust Mark, by contrast, is voluntary. These frameworks technically apply regardless of where the manufacturer sits. In practice, enforcing fines on a Shenzhen company that ignores CISA coordination requests is a different proposition entirely. How to stay safe There are practical steps you can take: Check independent security testing before buying connected devices Place IoT devices on a separate guest network Keep firmware updated Disable features you don’t need And ask yourself whether a vacuum really needs a camera. Many LiDAR-only models navigate effectively without video. If your device includes a camera or microphone, consider whether you’re comfortable with that exposure—or physically cover the lens when not in use. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comFeb 17, 2026extracted
Amazon Scraps Partnership With Surveillance Company After Super Bowl Ad Backlash
Amazon’s smart doorbell maker Ring has terminated a partnership with police surveillance tech company Flock Safety. The announcement follows a backlash that erupted after a 30-second Ring ad that aired during the Super Bowl featuring a lost dog that is found through a network of cameras, sparking fears of a dystopian surveillance society. But that feature, called Search Party, was not related to Flock. And Ring’s announcement doesn’t cite the ad as a reason for the “joint decision” for the cancellation. Ring and Flock said last year they were planning on working together to give Ring camera owners the option to share their video footage in response to law enforcement requests made through a Ring feature known as Community Requests. “Following a comprehensive review, we determined the planned Flock Safety integration would require significantly more time and resources than anticipated,” Ring’s statement said. “The integration never launched, so no Ring customer videos were ever sent to Flock Safety.” Flock reiterated that it never received Ring customer videos — and that ending the planned integration was a mutual decision that allows both companies to “best serve their respective customers.” In a statement, Flock added that it “remains dedicated to supporting law enforcement agencies with tools that are fully configurable to local laws and policies.” Flock is one of the nation’s biggest operators of automated license-plate reading systems. Its cameras are mounted in thousands of communities across the U.S., capturing billions of photos of license plates each month. The company has faced public outcry amid the Trump administration’s aggressive immigration enforcement crackdown. But Flock maintains that it does not partner with Immigration and Customs Enforcement (ICE), or contract out with any subagency of the Department of Homeland Security for direct access to its cameras. The company paused pilot programs with Customs and Border Protection and Homeland Security Investigations last year. Still, Flock says it doesn’t own the data captured by its cameras, its customers do. So if a police department, for example, chooses to collaborate with a federal agency like ICE, “Flock has no ability to override that decision,” the company notes on its website. Beyond the Flock partnership, Amazon has faced other surveillance concerns over its Ring doorbell cameras. In the Super Bowl ad, a lost dog is found with Ring’s Search Party feature, which the company says can “reunite lost dogs with their families and track wildfires threatening your community.” The clip depicts the dog being tracked by cameras throughout a neighborhood using artificial intelligence. Viewers took to social media to criticize it for being sinister, leaving many wondering if it would be used to track humans and saying they would turn the feature off. The Electronic Frontier Foundation, a nonprofit that focus on civil liberties related to digital technology, said this week that Americans should feel unsettled over the potential loss of privacy. “Amazon Ring already integrates biometric identification, like face recognition, into its products via features like ‘Familiar Faces’ which depends on scanning the faces of those in sight of the camera and matching it against a list of pre-saved, pre-approved faces,” the Foundation wrote Tuesday. “It doesn’t take much to imagine Ring eventually combining these two features: face recognition and neighborhood searches.” Democratic Sen. Edward Markey of Massachusetts also urged Amazon to discontinue its “Familiar Faces” technology. In a published letter addressed to Amazon CEO Andrew Jassy, Markey wrote that the backlash to the Super Bowl commercial “confirmed public opposition to Ring’s constant monitoring and invasive image recognition algorithms.” Related: Surveillance Firm Bypasses SS7 Protections to Retrieve User Location Related: Smart TV Surveillance? How Samsung and LG’s ACR Technology Tracks What You Watch
securityweek.comFeb 16, 2026extracted
Attacco cyber contro Coupang, critiche nella gestione della sicurezza interna
In Corea del Sud continua a far discutere l’attacco cyber contro la piattaforma di e-commerce Coupang, soprattutto per le modalità operative dell’operazione. Il furto di dati che ha colpito Coupang, il principale gruppo di e-commerce della Corea del Sud, non sarebbe il risultato di un attacco cyber, bensì di “un fallimento nella gestione della sicurezza informatica“. Un problema interno, dunque, più che esterno. È quanto emerge dalle prime conclusioni di un’indagine condotta dal Governo di Seoul. Secondo quanto riferito martedì dal Ministero della Scienza, l’intrusione sarebbe stata opera di un ex ingegnere dell’azienda, a conoscenza delle debolezze nel sistema di autenticazione. L’ex dipendente sarebbe riuscito a violare i sistemi informatici nell’aprile dello scorso anno. In seguito, avrebbe mantenuto l’accesso non autorizzato fino a novembre. Un primo tentativo di intrusione risalirebbe già al mese di gennaio. Le indagini delle autorità di Seoul Le autorità hanno sottolineato come l’episodio evidenzi carenze strutturali nei controlli di sicurezza e nei processi di gestione del personale. Hanno invitato Coupang a intervenire con urgenza “per rafforzare le proprie difese digitali“. Il caso sta continuando a sollevare forti preoccupazioni sulla protezione dei dati degli utenti e sulla capacità delle grandi piattaforme digitali di prevenire minacce interne. L’indagine è ancora in corso. Ulteriori dettagli sulle dimensioni della fuga di dati e sulle eventuali responsabilità penali potrebbero emergere nelle prossime settimane. L’attacco cyber contro Coupang Quello del data breach contro la piattaforma commerciale sudcoreana ha destato non poche preoccupazioni, sopratutto per la sua gestione. Coupang aveva reso noto, circa tre mesi fa, di aver subìto un attacco cyber su vasta scala. L’operazione si era tradotta nella pubblicazione dei dati personali di oltre 33 milioni di clienti. A rendere ancora più grave il fatto, dalle indagini della Polizia era emerso che la violazione dei server sarebbe cominciata il precedente 24 giugno. Tuttavia, aveva riportato la Reuters, “l’azienda non è venuta a conoscenza del problema fino al 18 novembre“. I limiti delle Telco in Corea del Sud Kang Hoon-sik, capo di gabinetto del presidente sudcoreano Lee Jae Myung, aveva affermato nel merito che i quattro principali incidenti cyber dal 2021 hanno tutti evidenziato le “lacune strutturali”. In particolare “nella protezione dei dati personali in Corea del Sud“. Negli ultimi mesi, la Corea del Sud è stata spesso al centro delle cronache per attacchi interni di hacker criminali. La violazione dei server di Coupang, di fatto, è avvenuta contemporaneamente a quella contro LG Uplus. Ad agosto, poi, il più grande operatore di telefonia mobile del Paese, SK Telecom, aveva ricevuto una multa di 134 miliardi di won (96,53 milioni di dollari) dopo un altro attacco informatico. In quel caso, c’era stata una fuga di dati di quasi 27 milioni di utenti. Più in generale, gli analisti hanno segnalato come tutte queste operazioni abbiano interessato i comparti nevralgici del ‘Sistema Paese’ sudcoreano. Ossia: le telecomunicazioni. Le società di carte di credito. Le startup tecnologiche. Varie agenzie governative. Per un miglioramento dei sistemi nazionali Mentre Seoul continua ad accusare la Cina e la Corea del Nord, diversi esperti hanno segnalato come i problemi restino fondamentalmente due. Il primo luogo, un sistema di sicurezza informatica che è frammentato e non centralizzato, dunque non unitario. Si è registrata inoltre la carenza di tecnici. Da qui, la moltiplicazione delle opportunità per i cyber criminali, con risposte spesso poco tempestive. Per questo, lo stesso Kang aveva affermato che l’incidente cyber contro Coupang, sarebbe dovuta “essere un’opportunità per migliorare il sistema di risarcimento punitivo“. Nell’occasione, infatti, “la sua applicazione non sarebbe avvenuta in modo tale da impedire una compromissione massiccia dei dati“.
cybersecitalia.itFeb 10, 2026extracted
Attacco cyber contro Coupang, confermate ulteriori fughe di dati
Il data breach contro Coupang ha avuto delle ripercussioni anche nei rapporti con gli Usa, oltreché sul mercato interno della Corea del Sud. L’attacco cyber contro Coupang non ha portato soltanto diverse fughe di dati ma anche un inasprimento delle relazioni commerciali, per la Corea del Sud, con gli Usa. L’azienda sudcoreana di e-commerce, quotata alla borsa statunitense, ha infatti confermato lo scorso giovedì che i dati di altri 165mila utenti sono stati divulgati a seguito della violazione. Tanto che la decisione di Donald Trump di aumentare i dazi sui prodotti sudcoreani dal 15% al 25% era “legata” alla questione Coupang, più altre su cui Washington sta concentrando la propria attenzione. Tra queste, c’era la mossa della Corea del Sud di inasprire la regolamentazione nei confronti degli operatori di piattaforme digitali che potrebbe avere ripercussioni sulle aziende statunitensi. L’attacco cyber contro Coupang Quello del data breach contro la piattaforma commerciale sudcoreana ha destato non poche preoccupazioni, sopratutto per la sua gestione. Coupang aveva reso noto, circa tre mesi fa, di aver subìto un attacco cyber su vasta scala. L’operazione si era tradotta nella pubblicazione dei dati personali di oltre 33 milioni di clienti. A rendere ancora più grave il fatto, dalle indagini della Polizia era emerso che la violazione dei server sarebbe cominciata il precedente 24 giugno. Tuttavia, aveva riportato la Reuters, “l’azienda non è venuta a conoscenza del problema fino al 18 novembre“. I limiti delle Telco in Corea del Sud Kang Hoon-sik, capo di gabinetto del presidente sudcoreano Lee Jae Myung, aveva affermato nel merito che i quattro principali incidenti cyber dal 2021 hanno tutti evidenziato le “lacune strutturali”. In particolare “nella protezione dei dati personali in Corea del Sud“. Negli ultimi mesi, la Corea del Sud è stata spesso al centro delle cronache per attacchi interni di hacker criminali. La violazione dei server di Coupang, di fatto, è avvenuta contemporaneamente a quella contro LG Uplus. Ad agosto, poi, il più grande operatore di telefonia mobile del Paese, SK Telecom, aveva ricevuto una multa di 134 miliardi di won (96,53 milioni di dollari) dopo un altro attacco informatico. In quel caso, c’era stata una fuga di dati di quasi 27 milioni di utenti. Più in generale, gli analisti hanno segnalato come tutte queste operazioni abbiano interessato i comparti nevralgici del ‘Sistema Paese’ sudcoreano. Ossia: le telecomunicazioni. Le società di carte di credito. Le startup tecnologiche. Varie agenzie governative. Come migliorare i sistemi nazionali Mentre Seoul continua ad accusare la Cina e la Corea del Nord, diversi esperti hanno segnalato come i problemi restino fondamentalmente due. Il primo luogo, un sistema di sicurezza informatica che è frammentato e non centralizzato, dunque non unitario. Si è registrata inoltre la carenza di tecnici. Da qui, la moltiplicazione delle opportunità per i cyber criminali, con risposte spesso poco tempestive. Per questo, lo stesso Kang aveva affermato che l’incidente cyber contro Coupang, sarebbe dovuta “essere un’opportunità per migliorare il sistema di risarcimento punitivo“. Nell’occasione, infatti, “la sua applicazione non sarebbe avvenuta in modo tale da impedire una compromissione massiccia dei dati“.
cybersecitalia.itFeb 6, 2026extracted
26th January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 26th January, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES RansomHub ransomware group has claimed responsibility for a cyber-attack on Luxshare, an electronics manufacturer of Apple, Nvidia, LG, Tesla, and others. The threat actors claimed access to 3D CAD models, circuit board designs, and engineering documentation. The company has not yet confirmed the breach. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat (Ransomware.Wins.Ransomhub.ta.*; Ransomware.Win.RansomHub) Dark-web threat actor has leaked an alleged database belonging to Under Armour, a US sportswear company, affecting 72 million customer records following a November ransomware attack. The claimed exposed data includes names, email addresses, genders, dates of birth, and addresses. Raaga, an India-based music streaming platform, has experienced a data breach involving 10.2 million user records, reportedly exfiltrated in December and later advertised on criminal forums. Exposed details include names, emails, demographics, locations, and passwords stored with unsalted MD5 hashes, raising credential stuffing and phishing risks. Germany’s Dresden State Art Collections (SKD), one of Europe’s oldest museum networks, has confirmed a cyberattack that resulted in widespread disruption to its digital infrastructure and communications. The incident disabled online ticket sales, visitor services, and the museum shop, forced on-site payments to cash-only, and limited digital and phone services, with no indication of data theft or exposure reported. AI THREATS Researchers discovered an indirect prompt-injection flaw in Gemini’s Google Calendar assistant that bypassed Calendar privacy controls via a malicious invite description. Gemini used Calendar.create to place summaries of the victim’s meetings into a new event readable by the attacker. Researchers uncovered a web attack technique where hidden prompts in benign pages call LLM API to generate polymorphic malicious JavaScript at runtime. This enables phishing and credential theft while evading signature-based detection and network filtering by leveraging AI service domains. Advanced language models such as GPT-5.2 and Opus 4.5 were observed generating working exploits for a previously unknown zero-day vulnerability in QuickJS, a JavaScript interpreter, including in hardened environments where automated systems can produce functional attack code with little to no human intervention. Across six different configurations, the systems produced over 40 distinct exploits. VULNERABILITIES AND PATCHES Three high severity vulnerabilities (CVE-2025-68143, CVE-2025-68144, CVE-2025-68145) were disclosed in mcp-server-git, Anthropic’s Git MCP server, enabling path traversal and argument injection exploitable via prompt injection to read or delete files and achieve remote code execution. Fixes available in versions 2025.9.25 and 2025.12.18. Zoom has fixed CVE-2026-22844, a critical command injection flaw in Zoom Node Multimedia Routers, used in Meeting Connector and Meetings Hybrid deployments. It enables participant remote code execution in versions before 5.2.1716.0, with no confirmed in-the-wild exploitation. Fortinet has confirmed active exploitation of a FortiCloud SSO auth bypass on fully patched FortiGate firewalls, tied to CVE-2025-59718 and CVE-2025-59719. Attackers are logging in via crafted SAML messages, creating persistent accounts, enabling VPN access, and extracting firewall configurations. THREAT INTELLIGENCE REPORTS Check Point Research revealed that VoidLink, a recently exposed cloud-native Linux malware framework, is authored almost entirely by AI, likely under the direction of a single individual. The malware was produced predominantly through AI-driven development, reaching the first functional implant in under a week. From a methodology perspective, the actor used the model beyond coding, adopting an approach called Spec Driven Development (SDD). Check Point Research identified an ongoing phishing campaign associated with KONNI, a North Korean–linked threat actor active since at least 2014. The campaign targets software developers and engineering teams across the Asia-Pacific region, including Japan, Australia, and India, using blockchain-themed lures to prompt interaction and deliver malicious content. In observed activity, the threat actor deploys AI-generated PowerShell backdoors that establish persistence, steal credentials, and enable infiltration of development environments Check Point researchers describe a Microsoft Teams phishing campaign abusing guest invitations and finance-themed team names to mimic billing notices. More than 12K emails were observed hitting 6,135 users via invite emails with obfuscated text. The campaign targeted US-based organizations across manufacturing, technology, and education. Researchers revealed a new ransomware family, Osiris, that blends legitimate Windows tools with custom malware to infiltrate networks and deploy encryption. The operators use a custom malicious driver, Poortry, masquerading as Malwarebytes to disable security software, and exfiltrated data with Rclone to Wasabi buckets before encryption. Researchers identified a North Korean spear-phishing campaign targeting South Korea that abuses Microsoft Visual Studio Code tunnels for remote access. JSE files masquerading as Hangul documents start the infection chain and grant attackers terminal and file access using living-off-the-land techniques.
research.checkpoint.comJan 26, 2026extracted
RansomHub claims alleged breach of Apple partner Luxshare
RansomHub claims alleged breach of Apple partner Luxshare Chinese electronic manufacturer and Apple partner Luxshare Precision Industry has allegedly been breached by affiliates of the RansomHub ransomware-as-a-service outfit. Luxshare is one of the primary assemblers of Apple’s wireless earbuds, iPhones, and Vision Pro devices, as well as a producer of components used in Apple devices. The company also counts NVIDIA, Qualcomm, Samsung, Intel, and other high-profile tech and automotive companies among its partners and clients. RansomHub’s (unconfirmed) claims According to a post on the group’s data leak site, the attackers stole and encrypted some of the company’s sensitive data. “Dear management of Luxshare Precision Industry Co. Ltd. We were waiting for you for quite some time, but it seems that your IT department decided to conceal the incident that took place in your company. We strongly recommend you to contact us to prevent your confidential data, projects documents from being leaked,” the group threatens. According to the post, among the stolen data are: Confidential 3D CAD product models, 3D engineering design data, and 3D engineering documentation High-precision geometric data for Parasolid products 2D component drawings for manufacturing and mechanical component drawings Engineering drawings in PDF format Printed circuit board design and manufacturing data “The archives contain data from Apple, Nvidia, as well as LG, Geely, Tesla, and other large companies whose production and R&D information is publicly available,” the group claims, and has offered for download packages of data as proof of the breach. We could not download and independently analyze the leaked packages, but Cybernews’ research team says that they contain “details on what appear to be confidential projects regarding device repair and shipping between Apple and Luxshare” and information about other Luxshare clients. Help Net Security has reached out to Luxshare for confirmation of the alleged breach and we’ll update this article if we hear back from them. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJan 21, 2026extracted
Texas court blocks Samsung from tracking TV viewing, then vacates order
Update Jan. 6, 2026, 1:49 PM ET: After publishing this story, Samsung told BleepingComputer that the Texas court vacated the temporary restraining order that blocked Samsung from collecting smart TV viewing data the next day. More information added at the end of the story and title updated. The State of Texas obtained a short-lived, temporary restraining order (TRO) against Samsung that prohibited the South Korean company from collecting audio and visual data about what Texas consumers are watching on their TVs. Like other major TV manufacturers, Samsung employs Automated Content Recognition (ACR) technology to capture periodic screenshots, analyze viewing activity, and identify users' content preferences. The data is used for more targeted advertising. Texas also filed lawsuits against Sony, LG, and China-based companies Hisense and TCL Technology Group Corporation last month, over unlawful use of ACR technology and concerns os US user data being accessed by China. Texas Attorney General Ken Paxton claims that ACR is used to capture screenshots every 500 milliseconds without consumers' knowledge or consent. The District Court of Collin County in Texas ruled that this activity violates the Texas Deceptive Trade Practices Act (DTPA) and ordered Samsung Electronics America Inc. and Samsung Electronics Co., Ltd to stop using, selling, collecting, and transferring data from Texas-based TVs until January 19. Signed on January 5th at 10:10 AM, the TRO document lists several justifications for the decision to issue a temporary restraining order, including Samsung’s deceptive ACR enrollment practices and the allegation "that the Chinese Communist Party (“CCP”) has access to the information." "The Court finds that there is good cause to believe that SAMSUNG’s process for enrolling consumers in the ACR data collection program is false, deceptive, or misleading because it does not disclose to consumers how much data is being collected about them, how the data is actually being used, and that the Chinese Communist Party (“CCP”) has access to the information," Temporary Restraining Order against Samsung Furthermore, the court highlights that the enrollment process is confusing and opaque, pressuring users to consent to ACR through "dark patterns," and making it practically impossible to fully opt out of the data collection mechanism, letting them only "limit the use" of the collected data. The court noted that users can consent to ACR data collection with a single click, but details about the program are available after enrollment, and reviewing the privacy statements and disclosures requires more than 200 clicks. “Consent from consumers is not informed, privacy choices are not meaningful, users cannot reasonably understand the surveillance model, and the system defaults towards maximal data extraction,” reads the TRO document. A TRO extends to all company "officers, agents, employees, and all other persons in active concert or participation with them" from continuing to use, sell, transfer, collect, or share ACR data relating to Texas consumers. Texas court vacates temporary restraining order One day after granting the TRO, the same judge ruled that it should not remain in effect and vacated the order. “The Court finds, sua sponte, that the [TRO obtained by the State of Texas against Samsung] should be set aside,” the judge wrote in the order. After publication of the original article, Samsung Electronics America told BleepingComputer that the TRO was vacated on Tuesday, January 6. A company representative also said that Samsung’s TRO hearing remains scheduled for Friday, January 9. While this does not end the lawsuit, the Texas Attorney General’s action did not ultimately prevent Samsung’s alleged collection of TV users’ viewing data. BleepingComputer has reached out to the Texas Attorney General's Office for a statement about the court nulifying the order and future action but a commment was not immediately available. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJan 8, 2026extracted
Attacco cyber contro Coupang, arrivano le scuse ufficiali, ma le aziende Telco della Corea del Sud sono sempre più vulnerabili
Protagonista di uno dei più grandi attacchi cyber della Corea del Sud, il fondatore di Coupang Kim Bom ha rivolto delle “scuse ufficiali” ai suoi clienti. Le scuse ufficiali di Kim Bom, il fondatore di Coupang (la piattaforma di e-commerce più popolare in Corea del Sud) non basteranno ad eludere il tema principale. Le grandi aziende Telco con sede a Seoul non sono sicure e il 2025 l’ha dimostrato a più riprese. La fuga di dati ha attirato l’attenzione dell’opinione pubblica e sollevato preoccupazioni – anche a livello istituzionale – sulla gestione delle informazioni personali degli utenti. Oltre alle scuse, Kim Bom ha promesso nuovi investimenti e riforme interne con l’obiettivo di “rafforzare la sicurezza informatica e prevenire futuri episodi simili“. La CNBC ha scritto che l’azienda “offrirà un risarcimento pari a 1,69 trilioni di won sudcoreani (1,17 miliardi di dollari) ai 34 milioni di utenti colpiti dalla massiccia violazione di dati“. Ai clienti saranno dati “buoni acquisto per un valore complessivo di 50.000 won da utilizzare per vari servizi Coupang“. L’attacco cyber contro Coupang Coupang aveva reso noto, circa un mese fa, di aver subìto un attacco cyber su vasta scala. L’operazione si era tradotta nella pubblicazione dei dati personali di oltre 33 milioni di clienti. A rendere ancora più grave il fatto, dalle indagini della Polizia era emerso che la violazione dei server sarebbe cominciata il precedente 24 giugno. Tuttavia, aveva riportato la Reuters, “l’azienda non è venuta a conoscenza del problema fino al 18 novembre“. I limiti delle Telco in Corea del Sud Kang Hoon-sik, capo di gabinetto del presidente sudcoreano Lee Jae Myung, aveva affermato nel merito che i quattro principali incidenti cyber dal 2021 hanno tutti evidenziato le “lacune strutturali”. In particolare “nella protezione dei dati personali in Corea del Sud“. Negli ultimi mesi, la Corea del Sud è stata spesso al centro delle cronache per attacchi interni di hacker criminali. La violazione dei server di Coupang, di fatto, è avvenuta contemporaneamente a quella contro LG Uplus. Ad agosto, poi, il più grande operatore di telefonia mobile del Paese, SK Telecom, aveva ricevuto una multa di 134 miliardi di won (96,53 milioni di dollari) dopo un altro attacco informatico. In quel caso, c’era stata una fuga di dati di quasi 27 milioni di utenti. Più in generale, gli analisti hanno segnalato come tutte queste operazioni abbiano interessato i comparti nevralgici del ‘Sistema Paese’ sudcoreano. Ossia: le telecomunicazioni. Le società di carte di credito. Le startup tecnologiche. Varie agenzie governative. Come migliorare i sistemi nazionali Mentre Seoul continua ad accusare la Cina e la Corea del Nord, diversi esperti hanno segnalato come i problemi restino fondamentalmente due. Il primo luogo, un sistema di sicurezza informatica che è frammentato e non centralizzato, dunque non unitario. Si è registrata inoltre la carenza di tecnici. Da qui, la moltiplicazione delle opportunità per i cyber criminali, con risposte spesso poco tempestive. Per questo, lo stesso Kang aveva affermato che l’incidente cyber contro Coupang, “dovrebbe essere un’opportunità per migliorare il sistema di risarcimento punitivo“. Nell’occasione, infatti, “la sua applicazione non sarebbe avvenuta in modo tale da impedire una compromissione massiccia dei dati“.
cybersecitalia.itDec 31, 2025extracted
ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories
It’s getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in — they’re blending in, hijacking everyday tools, trusted apps, and even AI assistants. What used to feel like clear-cut “hacker stories” now looks more like a mirror of the systems we all use. This week’s findings show a pattern: precision, patience, and persuasion. The newest campaigns don’t shout for attention — they whisper through familiar interfaces, fake updates, and polished code. The danger isn’t just in what’s being exploited, but in how ordinary it all looks. ThreatsDay pulls these threads together — from corporate networks to consumer tech — revealing how quiet manipulation and automation are reshaping the threat landscape. It’s a reminder that the future of cybersecurity won’t hinge on bigger walls, but on sharper awareness. Open-source tool exploitedBad actors are leveraging an open-source monitoring tool named Nezha to gain remote access to compromised hosts. Its ability to allow administrators to view system health, execute commands, transfer files, and open interactive terminal sessions also makes it an attractive choice for threat actors. In one incident investigated by Ontinue, the tool was deployed as a post-exploitation remote access tool by means of a bash script, while pointing to a remote dashboard hosted on Alibaba Cloud infrastructure located in Japan. "The weaponization of Nezha reflects an emerging modern attack strategy where threat actors systematically abuse legitimate software to achieve persistence and lateral movement while evading signature-based defenses," said Mayuresh Dani, security research manager at Qualys. The abuse of Nezha is part of broader efforts where attackers leverage legitimate tools to evade signature detection, blend with normal activity, and reduce development effort. Facial scans for SIMsSouth Korea will begin requiring people to submit to facial recognition when signing up for a new mobile phone number in a bid to tackle scams and identity theft, according to the Ministry of Science and ICT. "By comparing the photo on an identification card with the holder's actual face on a real-time basis, we can fully prevent the activation of phones registered under a false name using stolen or fabricated IDs," the ministry said. The new policy, which applies to SK Telecom, Korea Telecom, and LG Uplus, and other mobile virtual network operators, takes effect on March 23 after a pilot following a trial that began this week. The science ministry has emphasized that no data will be stored as part of the new policy. "We are well aware that the public is concerned due to a series of hacking incidents at local mobile carriers," the ministry said. "Contrary to concerns raised by some, no personal information is stored or saved, and it is immediately erased once identification is verified." Android NFC threat spikeData from ESET has revealed that detections of NFC-abusing Android malware grew by 87% between H1 and H2 2025. This increase has been coupled with the growing sophistication of NFC-based malware, such as the harvesting of victims' contacts, disabling of biometric verification, and bringing together NFC attacks with remote access trojan (RAT) features and Automated Transfer System (ATS) capabilities. In these campaigns, malicious apps distributing malware such as PhantomCard prompt victims to hold their payment card near the phone and enter their PIN for authentication. In the process, the captured information is relayed to the attackers. "Recent innovations in the NFC sphere demonstrate that threat actors no longer rely solely on relay attacks: they are blending NFC exploitation with advanced capabilities such as remote access and automated transfers," ESET said. "The efficiency of the scams is further fueled by advanced social engineering and technologies that can bypass biometric verification." Fake PoCs spread malwareThreat actors are now targeting inexperienced professionals and students in the information security field with fake proof-of-concept (PoC) exploits for security flaws such as CVE-2025-59295, CVE-2025-10294, and CVE-2025-59230 to trick them into installing WebRAT using a ZIP archive hosted in the repositories. "To build trust, they carefully prepared the repositories, incorporating detailed vulnerability information into the descriptions," Kaspersky said. The repositories include detailed sections with overviews of the vulnerability, system impact, install guides, usage steps, and even mitigation advice. The consistency of the format of a professional PoC write-up suggests the descriptions are machine-generated to avoid detection. Present within the ZIP file is an executable named "rasmanesc.exe," that's capable of escalating privileges, disabling Microsoft Defender, and fetching WebRAT from an external server. Webrat is a backdoor that allows attackers to control the infected system, as well as steal data from cryptocurrency wallets, Telegram, Discord, and Steam accounts. It can also perform spyware functions such as screen recording, surveillance via a webcam and microphone, and keylogging. WebRAT is sold by NyashTeam, which also advertises DCRat. GuLoader surge observedCampaigns distributing GuLoader (aka CloudEyE) scaled a new high between September and November 2025, according to ESET, with the highest detection peak recorded in Poland on September 18. "CloudEyE is multistage malware; the downloader is the initial stage and spreads via PowerShell scripts, JavaScript files, and NSIS executables," the company said. "These then download the next stage, which contains the crypter component with the intended final payload packed within. All CloudEyE stages are heavily obfuscated, meaning that they are deliberately difficult to detect and analyze, with their contents being compressed, encrypted, encoded, or otherwise obscured." Chatbot flaws exposedMultiple vulnerabilities have been disclosed in Eurostar’s public artificial intelligence (AI) chatbot that could allow guardrail bypass by taking advantage of the fact that the frontend relays the entire chat history to the API while running checks only on the latest message to ensure it's safe. This opens the door to a scenario where an attacker could tamper with earlier messages, which, when fed into the model's API, causes it to return unintended responses via a prompt injection. Other identified issues included the ability to modify message IDs to potentially lead to cross-user compromise and inject HTML code stemming from the lack of input validation. "An attacker could exfiltrate prompts, steer answers, and run scripts in the chat window," Pen Test Partners said. "The core lesson is that old web and API weaknesses still apply even when an LLM is in the loop." Some of these vulnerabilities have since been fixed, but not before a confusing disclosure process that saw the penetrating testing firm somehow being accused of blackmail by Eurostar's head of security on LinkedIn after asking, "Maybe a simple acknowledgement of the original email report would have helped?" Critical flaws uncoveredA hacking competition conducted by Wiz, zeroday.cloud, led to the discovery of 11 critical zero-day exploits affecting foundational open-source components used in critical cloud infrastructure, including container runtimes, AI infrastructure such as vLLM and Ollama, and databases like Redis, PostgreSQL, and MariaDB. The most severe of the flaws has been uncovered in Linux. "The vulnerability allows for a Container Escape, often enabling attackers to break out of an isolated cloud service, dedicated to one specific user, and spread to the underlying infrastructure that manages all users," Wiz said. "This breaks the core promise of cloud computing: the guarantee that different customers running on the same hardware remain separate and inaccessible to one another. This further reinforces that containers shouldn't be the sole security barrier in multi-tenant environments." Loader targets industriesManufacturing and government organizations in Italy, Finland, and Saudi Arabia are the target of a new phishing campaign that uses a commodity loader to deliver a wide range of malware, such as PureLogs, XWorm, Katz Stealer, DCRat, and Remcos RAT. "This campaign utilizes advanced tradecraft, employing a diverse array of infection vectors including weaponized Office documents (exploiting CVE-2017-11882), malicious SVG files, and ZIP archives containing LNK shortcuts," Cyble said. "Despite the variety of delivery methods, all vectors leverage a unified commodity loader." The use of the loader to distribute a variety of malware indicates that the loader is likely shared or sold across different threat actor groups. A notable aspect of the campaign is the use of steganographic techniques to host image files on legitimate delivery platforms, thereby allowing the malicious code to slip past file-based detection systems by masquerading as benign traffic. The commodity loader is assessed to be Caminho based on similar campaigns detailed by Nextron Systems and Zscaler. Teams gets safer defaultsMicrosoft has announced that Teams will automatically enable messaging safety features by default, including weaponizable file type protection, malicious URL protection, and reporting incorrect detections. The change will roll out starting January 12, 2026, to tenants that have not previously modified messaging safety settings and are still using the default configuration. "We're improving messaging security in Microsoft Teams by enabling key safety protections by default," Microsoft said in a Microsoft 365 message center update. "This update helps safeguard users from malicious content and provides options to report incorrect detections." In addition, the Windows maker said security administrators will be able to block external users in Microsoft Teams via the Tenant Allow/Block List in the Microsoft Defender portal. The feature is expected to roll out in early January 2026 and be completed by mid-January. "This centralized approach enhances security and compliance by enabling organizations to control external user access across Microsoft 365 services," the company said. AI assistant hijack riskDocker has patched a vulnerability in Ask Gordon, its AI assistant embedded in Docker Desktop and the Docker CLI. The flaw, discovered by Pillar Security in the beta version, is a case of prompt injection that enables attackers to hijack the assistant and exfiltrate sensitive data by poisoning Docker Hub repository metadata with malicious instructions. An attacker could have created a malicious Docker Hub repository that contained crafted instructions for the AI to exfiltrate sensitive data when unsuspecting developers ask the chatbot to describe the repository. "By exploiting Gordon's inherent trust in Docker Hub content, threat actors can embed instructions that trigger automatic tool execution – fetching additional payloads from attacker-controlled servers, all without user consent or awareness," security researcher Eilon Cohen said. The issue was addressed in version 4.50.0 released on November 6, 2025. Firewall bypass threatResearchers have demonstrated how to breach Internet of Things (IoT) devices through firewalls, without the need for any kind of software vulnerability. "We present a new attack technique that allows attackers anywhere in the world to impersonate target intranet devices, hijack cloud communication channels, spoof the cloud, and bypass companion app authentication, and ultimately achieve Remote Code Execution (RCE) with root privileges," researchers Jincheng Wang and Nik Xe said. "Our research exposes flaws in existing cloud-device authentication mechanisms, and a widespread absence of proper channel verification mechanisms." Faster BitLocker encryptionMicrosoft said it's rolling out hardware-accelerated BitLocker in Windows 11 to balance robust security with minimal performance impact. "Starting with the September 2025 Windows update for Windows 11 24H2 and the release of Windows 11 25H2, in addition to existing support for UFS (Universal Flash Storage) Inline Crypto Engine technology, BitLocker will take advantage of upcoming system on chip (SoC) and central processing unit (CPU) capabilities to achieve better performance and security for current and future NVMe drives," the company said. As part of this effort, BitLocker will hardware wrap BitLocker bulk encryption keys and offload bulk cryptographic operations from the main CPU to a dedicated crypto engine. "When enabling BitLocker, supported devices with NVMe drives, along with one of the new crypto offload capable SoCs, will use hardware-accelerated BitLocker with the XTS-AES-256 algorithm by default," the tech giant added. Israel-targeted phishingInformation Technology (IT), Managed Service Providers (MSPs), human resources, and software development companies in Israel have become the target of a threat cluster likely originating from Western Asia that has used phishing lures written in Hebrew and designed to resemble routine internal communications to infect their systems with a Python- and Rust-based implants tracked as PYTRIC and RUSTRIC. The activity has been tracked by Seqrite Labs under the monikers UNG0801 and Operation IconCat. "A recurring pattern across the observed campaigns is the actor's heavy reliance on antivirus icon spoofing," the company said. "Branding from well-known security vendors, most notably SentinelOne and Check Point, is abused to create a false sense of legitimacy." The PDF attachment in the email messages instructs recipients to download a security scanner by clicking on a Dropbox link that delivers the malware. PYTRIC is equipped to scan the file system and perform a system-wide wipe. Attack chains distributing RUSTRIC leverage Microsoft Word documents with a malicious macro, which then extracts and launches the malware. Besides enumerating the antivirus programs installed on the infected host, it gathers basic system information and contacts an external server. EDR killer tool soldA threat actor known as AlphaGhoul is promoting a tool called NtKiller that they claim can stealthily terminate antivirus and security solutions, such as Microsoft Defender, ESET, Kaspersky, Bitdefender, and Trend Micro. The core functionality, per Outpost24, is available for $500, with a rootkit add-on and a UAC Bypass add-on costing $300 each. The disclosure comes weeks after a security researcher, who goes by the name Zero Salarium, demonstrated how Endpoint Detection and Response (EDR) programs can be undermined on Windows by exploiting the Bind Filter driver ("bindflt.sys"). In recent months, the security community has also identified ways to bypass web application firewalls (WAFs) by abusing ASP.NET's parameter pollution, subvert EDRs using an in-memory Portable Executable (PE) loader, and even manipulate Microsoft Defender Antivirus to sideload DLLs and delete executable files to prevent the service from running by exploiting its update mechanism to hijack its execution folder. AI exploits blockchainAI company Anthropic said Claude Opus 4.5, Claude Sonnet 4.5, and GPT-5 developed exploits in blockchain smart contracts that would have allowed the theft of $4.6 million worth of digital assets. "Both agents uncovered two novel zero-day vulnerabilities and produced exploits worth $3,694, with GPT-5 doing so at an API cost of $3,476," Anthropic's Frontier Red Team said. "This demonstrates as a proof-of-concept that profitable, real-world autonomous exploitation is technically feasible, a finding that underscores the need for proactive adoption of AI for defense." North Korea’s new lureThe North Korean threat actor known as ScarCruft has been linked to a new campaign dubbed Artemis that involves the adversary posing as a writer for Korean TV programs to reach out to targets for casting or interview arrangements. "A short self-introduction and legitimate-looking instructions are used to build trust," Genians said. "The attacker distributes a malicious HWP file disguised as a pre-interview questionnaire or event guide document." The end goal of these attacks is to trigger the sideloading of a rogue DLL that ultimately delivers RokRAT, which uses Yandex Cloud for command-and-control (C2). The campaign gets its name from the fact that one of the identified HWP documents has its Last Saved By field set to the value "Artemis." AI-fueled disinfo surgeThe Russian influence operation CopyCop (aka Storm-1516) is using AI tools to scale its efforts to a global reach, quietly deploying more than 300 inauthentic websites disguised as local news outlets, political parties, and even fact-checking organizations targeting audiences across North America, Europe, and other regions, including Armenia, Moldova, and parts of Africa. The primary objective is to further Russia's geopolitical goals and erode Western support for Ukraine. "What sets CopyCop apart from earlier influence operations is its large-scale use of artificial intelligence," Recorded Future said. "The network relies on self-hosted LLMs, specifically uncensored versions of a popular open-source model, to generate and rewrite content at scale. Thousands of fake news stories and 'investigations' are produced and published daily, blending factual fragments with deliberate falsehoods to create the illusion of credible journalism." RomCom-themed phishingA threat cluster dubbed SHADOW-VOID-042 has been linked to a November 2025 spear-phishing campaign featuring a Trend Micro-themed social engineering lure to trick victims in the defense, energy, chemical, cybersecurity (including Trend and a subsidiary), and ICT sectors with messages instructing them to install a fake update for alleged security issues in Trend Micro Apex One. The activity, Trend Micro said, shares overlaps with prior campaigns attributed to RomCom (aka Void Rabisu), a threat actor with both financial and espionage motivations that aligned with Russian interests. However, in the absence of a definitive connection, the latter attack waves are being tracked under a separate temporary intrusion set. What's more, the November 2025 campaign shares tactical and infrastructure overlaps with another campaign in October 2025, which used alleged harassment complaints and research participation as social engineering lures. "The campaign utilized a multi-stage approach, tailoring every stage to the specific target machine and delivering intermediate payloads to a select number of targets," Trend Micro said. The URLs embedded in the emails redirect victims to a fake landing page impersonating Cloudflare, while, in the background, attempts are made to exploit a now-patched Google Chrome security flaw (CVE-2018-6065) using a JavaScript file. In the event exploitation fails, they are taken to a decoy site named TDMSec, impersonating Trend Micro. The JavaScript file also contains shellcode responsible for gathering system information and contacting an external server to fetch a second-stage payload, which acts as a loader for an encrypted component that then proceeds to contact a server to obtain an unspecified next-stage malware. While Void Rabisu has exploited zero-days in the past, the new findings raise the possibility that it could be undergoing several changes. The stories this week aren’t just about new attacks — they’re a snapshot of how the digital world is maturing under pressure. Every exploit, fake lure, or AI twist is a sign of systems being tested in real time. The takeaway isn’t panic; it’s awareness. The more we understand how these tactics evolve, the less power they hold. Cybersecurity now sits at the crossroads of trust and automation. As AI learns to defend, it’s also learning how to deceive. That tension will define the next chapter — and how ready we are to face it depends on what we choose to notice today. Stay curious, stay skeptical, and read between the lines. The biggest threats often hide in what feels most routine — and that’s exactly where the next breakthrough in defense will begin.
thehackernews.comDec 25, 2025extracted
⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More
Cyber threats last week showed how attackers no longer need big hacks to cause big damage. They’re going after the everyday tools we trust most — firewalls, browser add-ons, and even smart TVs — turning small cracks into serious breaches. The real danger now isn’t just one major attack, but hundreds of quiet ones using the software and devices already inside our networks. Each trusted system can become an entry point if it’s left unpatched or overlooked. Here’s a clear look at the week’s biggest risks, from exploited network flaws to new global campaigns and fast-moving vulnerabilities. ⚡ Threat of the Week Flaws in Multiple Network Security Products Come Under Attack — Over the past week, Fortinet, SonicWall, Cisco, and WatchGuard said vulnerabilities in their products have been exploited by threat actors in real-world attacks. Cisco said attacks exploiting CVE-2025-20393, a critical flaw in AsyncOS, have been abused by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686 to deliver malware such as ReverseSSH (aka AquaTunnel), Chisel, AquaPurge, and AquaShell. The flaw remains unpatched. SonicWall said attacks exploiting CVE-2025-40602, a local privilege escalation flaw impacting Secure Mobile Access (SMA) 100 series appliances, have been observed in connection with CVE-2025-23006 (CVSS score 9.8) to achieve unauthenticated remote code execution with root privileges. The development comes as firewalls and edge appliances have become a favorite target for attackers, giving attackers deeper visibility into traffic, VPN connections, and downstream systems. Cyber Forum 2026: Adversary Trends, AI Innovation, and the Future of Security Ops A virtual cybersecurity forum for today’s security leaders. Discover how AI and automation strengthen defenses, streamline operations, and deliver measurable business impact. Hear from security leaders and research experts and get actionable strategies and trends. Register for free today. Secure Your Seat ➝ 🔔 Top News Featured Chrome Extension Caught Harvesting AI Chats — Urban VPN Proxy, a Google Chrome and Microsoft Edge extension, with more than 7.3 installations, was observed stealthily gathering every prompt entered by users into artificial intelligence (AI)-powered chatbots like OpenAI ChatGPT, Anthropic Claude, Microsoft Copilot, DeepSeek, Google Gemini, xAI Grok, Meta AI, and Perplexity. Three other extensions from the same developer, 1ClickVPN Proxy, Urban Browser Guard, and Urban Ad Blocker, were also updated with similar functionality. Collectively, these add-ons were installed more than eight million times. The extensions are no longer available for download from the Chrome Web Store. Ink Dragon Targets Governments with ShadowPad and FINALDRAFT — The threat actor known as Jewelbug (CL-STA-0049, Earth Alux, Ink Dragon, and REF7707) has been increasingly focusing on government targets in Europe since July 2025, even as it continues to attack entities located in Southeast Asia and South America. The campaign has "impacted several dozen victims, including government entities and telecommunications organizations, across Europe, Asia, and Africa." Ink Dragon does not merely use victims for data theft but actively repurposes them to support ongoing operations against other targets of interest. This creates a self-sustaining infrastructure that obscures the true origin of the attacks while maximizing the utility of every compromised asset. Kimwolf Botnet Hijacks 1.8 Million Android TVs — A new botnet named Kimwolf is powered by no less than 1.8 million Android TVs. Infections are scattered globally, with Brazil, India, the U.S., Argentina, South Africa, and the Philippines registering higher concentrations. Kimwolf is believed to share its origins with AISURU, which has been behind some of the record-breaking DDoS attacks over the past year. It's suspected that the attackers reused code from AISURU in the early stages, before opting to develop the Kimwolf botnet to evade detection. QiAnXin XLab said it's possible some of these attacks may not have come from AISURU alone, and that Kimwolf may be either participating or even leading the efforts. LongNosedGoblin Uses Group Policy For Malware Deployment — A previously undocumented China-aligned threat cluster dubbed LongNosedGoblin has been attributed to a series of cyber attacks targeting governmental entities in Southeast Asia and Japan. Central to the group's tradecraft is the abuse of Group Policy to deploy malware across the compromised network and cloud services for communication with infected endpoints using a backdoor dubbed NosyDoor. The threat actor is believed to be active since at least September 2023. The exact initial access methods used in the attacks are presently unknown. Kimsuky Uses DocSwap Android Malware — The North Korean threat actor known as Kimsuky has been linked to a new campaign that distributes a new variant of Android data gathering malware called DocSwap via QR codes hosted on phishing sites mimicking Seoul-based logistics firm CJ Logistics (formerly CJ Korea Express). The apps masquerade as package delivery service apps. It's believed that the threat actors are using smishing texts or phishing emails impersonating delivery companies to deceive recipients into clicking on booby-trapped URLs hosting the apps. A noteworthy aspect of the attack is its QR code-based mobile redirection, which prompts users visiting the URLs from a desktop computer to scan a QR code displayed on the page on their Android device to install the supposed shipment tracking app and look up the status. ️🔥 Trending CVEs Hackers act fast. They can use new bugs within hours. One missed update can cause a big breach. Here are this week’s most serious security flaws. Check them, fix what matters first, and stay protected. This week’s list includes — CVE-2025-14733 (WatchGuard), CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, CVE-2025-14304 (pre-boot DMA protection Bypass), CVE-2025-37164 (HPE OneView Software), CVE-2025-59374 (ASUS Live Update), CVE-2025-20393 (Cisco AsyncOS), CVE-2025-40602 (SonicWall SMA 100 Series), CVE-2025-66430 (Plesk), CVE-2025-33213 (NVIDIA Merlin Transformers4Rec for Linux), CVE-2025-33214 (NVIDIA NVTabular for Linux), CVE-2025-54947 (Apache StreamPark), CVE-2025-13780 (pgAdmin), CVE-2025-34352 (JumpCloud Agent), CVE-2025-14265 (ConnectWise ScreenConnect), CVE-2025-40806, CVE-2025-40807 (Siemens Gridscale X Prepay), CVE-2025-32210 (NVIDIA Isaac Lab), CVE-2025-64374 (Motors WordPress theme), CVE-2025-64669 (Microsoft Windows Admin Center), CVE-2025-46295 (Apache Commons Text), CVE-2025-68154 (systeminformation), CVE-2025-14558 (FreeBSD), and cross-site scripting and information disclosure flaws in Roundcube Webmail (no CVEs). 📰 Around the Cyber World FBI Warns of Campaigns Impersonating Government Officials — The U.S. Federal Bureau of Investigation (FBI) has warned that malicious actors have impersonated senior U.S. state government, White House, and Cabinet-level officials, as well as members of Congress, to target individuals, including officials' family members and personal acquaintances, since at least 2023. The "Malicious actors have sent text messages and AI-generated voice messages — techniques known as smishing and vishing, respectively — that claim to come from a senior U.S. official to establish rapport with targeted individuals," the FBI said. "In the scheme, actors contact an individual and briefly engage on a topic the victim is versed on, with a request to move communication to a secondary, encrypted mobile messaging application, happening almost immediately." Once the conversation has shifted to Signal or WhatsApp, the threat actors urge victims to provide an authentication code that allows the actors to sync their device with the victim's contact list, share Personally Identifiable Information (PII) and copies of sensitive personal documents, wire funds to an overseas financial institution under false pretenses, and request them to introduce the actor to a known associate. Noyb Files Complaint Against TikTok, AppsFlyer and Grindr — Austrian privacy non-profit noyb has filed complaints against TikTok, AppsFlyer, and Grindr, accusing the popular video sharing platform of unlawfully tracking users across apps in violation of GDPR laws in the region. "A user found out about this unlawful tracking practice through an access request -- which showed that, e.g. his usage of Grindr was sent to TikTok, likely via the Israeli tracking company AppsFlyer -- which allows TikTok to draw conclusions about his sexual orientation and sex life," noyb said. "TikTok initially even withheld this information from the user, which violates Article 15 GDPR. Only after repeated inquiries, TikTok revealed that it knows which apps he used, what he did within these apps (for example, adding a product to the shopping cart) - and that this data also included information about his usage of the gay dating app Grindr." AuraStealer Spotted in the Wild — An emerging malware-as-a-service (MaaS) information stealer called AuraStealer has been distributed via Scam-Yourself campaigns, where victims are lured by TikTok videos disguised as product activation guides. "Viewers are instructed to manually retype and run a displayed command in an administrative PowerShell, which, however, instead of activating the software, quietly downloads and executes the malicious payload," Gen Digital said. "Apart from TikTok Scam-Yourself campaigns, AuraStealer is also distributed through supposedly cracked games or software, with delivery chains of varying complexity." AuraStealer makes use of a long list of anti-analysis and obfuscation techniques, including indirect control flow obfuscation, string encryption, and exception-driven API hashing, to resist attempts to reverse engineer the malware. It's capable of harvesting data from Chromium- and Gecko-based browsers, cryptocurrency wallets from desktop applications and browser extensions, clipboard contents, session tokens, credentials, VPNs, password managers, screenshots, and detailed system metadata. Also detected in the wild are two other information stealers named Stealka and Phantom, with the latter distributed via fake Adobe installers. Blind Eagle Continues to Attack Colombia — Colombian institutions have continued to face attacks from a threat actor known as Blind Eagle. The latest phishing attacks, targeting agencies under the Ministry of Commerce, Industry and Tourism (MCIT), have shifted to a more sophisticated, multi-layer flow that uses an off-the-shelf loader named Caminho to deliver DCRat. The messages are sent from compromised email accounts within the same organization to bypass security checks. "The phishing email used a legal-themed design to lure the recipient," Zscaler said. "The email was created to appear as an official message from the Colombian judicial system, referencing a labor lawsuit with an authentic-sounding case number and date. The email pressures the recipient to confirm receipt immediately, leveraging authority, fear of legal consequences, and confidentiality warnings to trick the recipient into taking an action, namely opening the attachment." Scripted Sparrow Linked to Large-Scale BEC Attacks — A sprawling Business Email Compromise (BEC) collective known as Scripted Sparrow has been observed distributing more than three million email messages each month and refining its social-engineering playbook. "The scale of the group's operation strongly suggests the use of automation to generate and send their attack messages," Fortra said. "The group utilizes a combination of free webmail addresses as well as addresses on domains they've registered specifically for their operations. The group operates by posing as various executive coaching and leadership training consultancies." First discovered in June 2024, the "loose collective of fraudsters" has members located in Nigeria, South Africa, Türkiye, Canada, and the U.S. The group is estimated to have registered 119 domains and used 245 webmail addresses. It has also used 256 bank accounts to move money out of victims' bank accounts. Smart Devices Run Outdated Browser Versions — An academic study by a team of Belgian researchers has found that a majority of smart devices, such as smart TVs, e-readers, and gaming consoles, come with an embedded web browser that runs extremely outdated versions, sometimes as much as three years. All five e-readers that were tested, and 24 of 35 smart TV models, used embedded browsers that were at least three years behind current versions available to users of desktop computers. These outdated, embedded browsers can leave users open to phishing and other security vulnerabilities. The authors said some of the issues lie in how development frameworks like Electron bundle browsers with other components. "We suspect that, for some products, this issue stems from the user-facing embedded browser being integrated with other UI components, making updates challenging – especially when bundled in frameworks like Electron, where updating the browser requires updating the entire framework," they said in the paper. "This can break dependencies and increase development costs." Denmark Blames Russia For Attack on Water Utility — The Danish Defence Intelligence Service (DDIS) has blamed Russia for recent destructive and disruptive cyber attacks against the country, including a water utility in 2024, as well as distributed denial-of-service (DDoS) attacks on Danish websites in the run-up to the 2025 municipal and regional council elections. The attacks have been attributed to pro-Russian hacktivist groups Z-Pentest and NoName057(16), respectively. "The Russian state uses both groups as instruments of its hybrid war against the West. The aim is to create insecurity in the targeted countries and to punish those who support Ukraine," the DDIS said. "Russia’s cyber operations form part of a broader influence campaign intended to undermine Western support for Ukraine." The statement comes a few days after a global cybersecurity advisory warned that pro-Russian hacktivist groups conduct opportunistic attacks against US and global critical infrastructure. Russia Targeted by Arcane Werewolf — Russian manufacturing companies have become the target of a threat actor known as Arcane Werewolf (aka Mythic Likho). Campaigns undertaken by the hacking group in October and November 2025 likely leveraged phishing emails as the initial access vector that presumably contained links to a malicious archive hosted on the attackers' server. The links directed victims to a spoofed website imitating a Russian manufacturing company. The end goal of the attacks is to deploy a custom implant named Loki 2.1 by means of a loader that's delivered using a Go-based dropper downloaded from an external server using PowerShell code embedded into a Windows shortcut (LNK) contained in the ZIP file. In an attack chain detected in November 2025, a new C++ dropper was used to propagate the malware. Loki 2.1 is equipped to upload/download files, inject code into a target process, terminate arbitrary processes, retrieve environment variables, and stop its own execution. RansomHouse Upgrades to Complex Encryption — The RansomHouse (aka Jolly Scorpius) ransomware group has upgraded its file encryption process to use two different encryption keys to encrypt files as part of their attacks in what has been described as a significant escalation and "concerning trajectory" in ransomware development. "The upgraded version's code reveals a two-factor encryption scheme where the file is encrypted with both a primary key and a secondary key. Data encryption is processed separately for each key," Palo Alto Networks Unit 42 said. "This significantly increases the difficulty of decrypting the data without both keys." The e-crime group has been active since December 2021, listing 123 victims on its data leak site. Central to the threat actor's operations is a tool called MrAgent that provides attackers with persistent access to a victim's environment and simplifies managing compromised hosts at scale. It's also responsible for deploying Mario to encrypt critical VM files in the ESXi hypervisor. LLMs and Ransomware Lifecycle — The emergence of large language models (LLMs) is likely accelerating the ransomware lifecycle, according to new findings from SentinelOne. "We observe measurable gains in speed, volume, and multilingual reach across reconnaissance, phishing, tooling assistance, data triage, and negotiation, but no step-change in novel tactics or techniques driven purely by AI at scale," the company said. LLMs, including those that are deployed locally, can be used to replace the manual effort associated with drafting phishing emails and localized content, search for sensitive data, and develop malicious code. The continued sightings of various dark LLMs show that criminals are gravitating toward uncensored models that allow them to evade guardrails. "Actors already chunk malicious code into benign prompts across multiple models or sessions, then assemble offline to dodge guardrails," SentinelOne said. "This workflow will become commoditized as tutorials and tooling proliferate, ultimately maturing into 'prompt smuggling as a service.'" The findings signal that the barrier to entry into cybercrime continues to drop, even as the ransomware ecosystem is splintering and the line between nation-state and crimeware activity is increasingly blurring. The use of the technology is also likely to blur existing assessment lines around tradecraft and attribution, owing to the fact that the capabilities even allow smaller groups to acquire capabilities that were once limited to advanced state-backed actors. TikTok Signs Agreement to Create New U.S. Joint Venture — Nearly a year after TikTok's operations were briefly banned in the U.S. for national security concerns, the popular video-sharing platform said it has finalized a deal to move a substantial portion of its U.S. business under a new joint venture named TikTok USDS Joint Venture LLC. According to reports from Axios, Bloomberg, CNBC, and The Hollywood Reporter, the company has signed agreements with the three managing investors: Oracle, Silver Lake, and Abu Dhabi-based MGX. Together, those companies will own 45% of the U.S. operation, while ByteDance retains a nearly 20% share. The new entity is said to be responsible for protecting U.S. data, ensuring the security of its prized algorithm, content moderation, and "software assurance." Oracle will be the trusted security partner in charge of auditing and validating compliance. The agreement is set to go into effect on January 22, 2026. Under a national security law, China-based ByteDance was required to divest TikTok's U.S. operations or face an effective ban in the country. The U.S. government has since extended the ban four times as a deal was being hatched behind the scenes. Under President Donald Trump's executive order in September, the attorney general was blocked from enforcing the national security law for a 120-day period in order to "permit the contemplated divestiture to be completed," allowing the deal to finalize by January 23, 2026. Android Adware Campaign Targets East and Southeast Asia — Android users in the Philippines, Pakistan, and Malaysia have been targeted by a large-scale Android adware campaign dubbed GhostAd that silently drains resources and disrupts normal phone use through persistent background activity. The set of 15 apps, distributed via Google Play, masqueraded as harmless utility and emoji-editing tools such as Vivid Clean and GenMoji Studio. "Behind their cheerful icons, these apps created a persistent background advertising engine – one that kept running even after users closed or rebooted their devices, quietly consuming battery and mobile data," Check Point said. "GhostAd integrates multiple legitimate advertising software development kits (SDKs), including Pangle, Vungle, MBridge, AppLovin, and BIGO, but uses them in a way that violates fair-use policies. Instead of waiting for user interaction, the apps continuously load, queue, and refresh ads in the background, using Kotlin coroutines to sustain the cycle." The apps have since been removed by Google, but not before they amassed millions of downloads. Texas Sues TV Makers for Spying on Owners — Texas Attorney General Ken Paxton accused Sony, Samsung, LG, Hisense, and TCL of spying on their customers and illegally collecting their data by using automatic content recognition (ACR), according to a new lawsuit. "ACR in its simplest terms is an uninvited, invisible digital invader," Paxton said. "This software can capture screenshots of a user’s television display every 500 milliseconds, monitor viewing activity in real time, and transmit that information back to the company without the user’s knowledge or consent. This conduct is invasive, deceptive, and unlawful." Cybercriminals Entice Insiders with High Payouts — Check Point has called attention to dark web posts that aim to recruit insiders within organizations to gain access to corporate networks, user devices, and cloud environments. The activity targets the financial sector and cryptocurrency firms, as well as companies like Accenture, Genpact, Netflix, and Spotify. The ads offer payouts from $3,000 to $15,000 for access or data. "Across darknet forums, employees are being approached, or even volunteering, to sell access or sensitive information for lucrative rewards," the company said. When internal staff disable defenses, leak credentials, or provide privileged information, preventing an attack becomes exponentially harder. Monitoring the deep web and darknet for organizational mentions or stolen data is now as critical as deploying advanced cyber prevention technologies." Flaws in Anno 1404 Game — Synacktiv researchers have disclosed multiple vulnerabilities in a strategy game named Anno 1404 that, if chained together, allow for arbitrary code execution from within the multiplayer mode. JSCEAL Campaign Undergoes a Shift — A Facebook ads campaign that's used to distribute a compiled V8 JavaScript (JSC) malware called JSCEAL has evolved into a more sophisticated form, with the attackers adopting a revamped command-and-control (C2) infrastructure, enhanced anti-analysis safeguards, and an updated script engine designed for increased stealth. "In contrast to the 1H 2025 campaign, which relied primarily on .com domains, the August 2025 campaign includes a broader variety of top-level domains such as .org, .link, .net, and others," Cato Networks said. "These domains are registered in bulk at regular intervals, suggesting an automated, scalable provisioning workflow." What's more, the updated infrastructure enforces stricter filtering and anti-analysis controls, blocking any HTTP request that does not present a PowerShell User-Agent. In the event a request includes the correct PowerShell User-Agent, the server responds with a fake PDF error rather than delivering the actual payload. It's only after the PDF has been returned that the C2 server delivers the next stage, including a modified version of the ZIP file containing the stealer malware. Third Defendant Pleads Guilty to Hacking Fantasy Sports and Betting Website — Nathan Austad, 21, of Farmington, Minnesota, has pleaded guilty in connection with a scheme to hack thousands of user accounts at an unnamed fantasy sports and betting website and sell access to those accounts with the goal of stealing hundreds of thousands of dollars from users. Austad and others launched a credential stuffing attack on the website in November 2022 and fully compromised approximately 60,000 user accounts. "In some instances, Austad and his co-conspirators were able to add a new payment method of their own on the account (i.e., to a newly added financial account belonging to the hacker) and then use it to withdraw all the existing funds in the victim account to themselves, thus stealing the funds in each affected Victim Account," the U.S. Justice Department said. "Using this method, Austad and others stole approximately $600,000 from approximately 1,600 victim accounts on the Betting Website." Access to the victim accounts was then sold on various websites that traffic in stolen accounts. Drop in Critical CVEs in 2025 — The number of critical vulnerabilities flagged in 2025 is at 3,753, down from 4,629 in 2023 and 4,283 in 2024, even as the total number of CVEs has increased to more than 40,000. According to VulnCheck, about 25.9% of the 43,002 CVEs published in 2025 have been enriched with a CVSS v4 score. "What this ultimately suggests is that CVSS v4 adoption is constrained not by lack of availability, but by limited participation from some of the largest and most influential CVE publishers and enrichers," it said. "Commonly cited reasons include resource constraints, required tooling changes, and a perception that CVSS v4 provides limited additional value while increasing scoring complexity and operational overhead." Amadey Uses Self-Hosted GitLab Instance to Distribute StealC — A new Amadey malware loader campaign has leveraged an exploited self-hosted GitLab instance ("gitlab.bzctoons[.]net") to deliver the StealC infostealer. "This analysis reveals how threat actors are hijacking abandoned, self-hosted GitLab servers to create a legitimate-looking payload distribution infrastructure," Trellix said. "The use of a long-standing domain with valid TLS certificates provides an effective evasion technique against traditional security controls." While the domain appears to belong to a small-scale organization hosting GitLab with multiple users, evidence suggests that either the user account or the entire infrastructure has been compromised. U.S. Dismantles E-Note Cryptocurrency Exchange — U.S. authorities seized the servers and infrastructure of the E-Note cryptocurrency exchange ("e-note.com," "e-note.ws," and "jabb.mn") for allegedly laundering more than $70 million from ransomware attacks and account takeover attacks since 2017. No arrests have been announced. In tandem, authorities have also indicted the site's operator, a 39-year-old Russian national named Mykhalio Petrovich Chudnovets, who is said to have started offering money laundering services to cybercriminals in 2010. Chudnovets has been charged with one count of conspiracy to launder monetary instruments, which carries a maximum penalty of 20 years in prison. The takedown fits into a broader law enforcement effort aimed at taking down services that allow bad actors to abuse the financial system and cash out the ill-gotten proceeds. 🎥 Cybersecurity Webinars How Zero Trust and AI Catch Attacks With No Files, No Binaries, and No Indicators — Cyber threats are evolving faster than ever, exploiting trusted tools and fileless techniques that evade traditional defenses. This webinar reveals how Zero Trust and AI-driven protection can uncover unseen attacks, secure developer environments, and redefine proactive cloud security—so you can stay ahead of attackers, not just react to them. Master Agentic AI Security: Learn to Detect, Audit, and Contain Rogue MCP Servers — AI tools like Copilot and Claude Code help developers move fast, but they can also create big security risks if not managed carefully. Many teams don’t know which AI servers (MCPs) are running, who built them, or what access they have. Some have already been hacked, turning trusted tools into backdoors. This webinar shows how to find hidden AI risks, stop shadow API key problems, and take control before your AI systems create a breach. 🔧 Cybersecurity Tools Tracecat — It is an open-source automation platform designed for security and IT teams that need flexible, scalable workflow orchestration. It combines simple YAML-based integration templates with a no-code interface for building workflows, along with built-in lookup tables and case management. Under the hood, workflows are orchestrated using Temporal to support reliability and scale, making Tracecat suitable for both local experimentation and production environments. Metis — It is an open-source, AI-powered security code review tool built by Arm’s Product Security Team. It uses large language models to understand code context and logic, helping engineers find subtle security issues that traditional tools often miss. Metis supports multiple languages through plugins, works with different LLM providers, and is designed to reduce review fatigue in large or complex codebases while improving secure coding practices. Disclaimer: These tools are for learning and research only. They haven’t been fully tested for security. If used the wrong way, they could cause harm. Check the code first, test only in safe places, and follow all rules and laws. Conclusion The past week made one point clear: the perimeter is gone, but accountability isn’t. Every device, app, and cloud service now plays a part in defense. Patching fast, verifying what’s running, and questioning defaults are no longer maintenance tasks — they’re survival skills. As threats grow more adaptive, resilience comes from awareness and speed, not fear. Keep visibility high, treat every update as risk reduction, and remember that most breaches start with something ordinary left unchecked.
thehackernews.comDec 22, 2025extracted
Texas sues TV makers for taking screenshots of what people watch
The Texas Attorney General sued five major television manufacturers, accusing them of illegally collecting their users' data by secretly recording what they watch using Automated Content Recognition (ACR) technology. The lawsuits target Sony, Samsung, LG, and China-based companies Hisense and TCL Technology Group Corporation. Attorney General Ken Paxton's office also highlighted "serious concerns" about the two Chinese companies being required to follow China's National Security Law, which could give the Chinese government access to U.S. consumers' data. According to complaints filed this Monday in Texas state courts, the TV makers can allegedly use ACR technology to capture screenshots of television displays every 500 milliseconds, monitor the users' viewing activity in real time, and send this information back to the companies' servers without the users' knowledge or consent. Paxton's office described ACR technology as "an uninvited, invisible digital invader" designed to unlawfully collect personal data from smart televisions, alleging that the harvested information then gets sold to the highest bidder for ad targeting. "Companies, especially those connected to the Chinese Communist Party, have no business illegally recording Americans' devices inside their own homes," Paxton said. "This conduct is invasive, deceptive, and unlawful. The fundamental right to privacy will be protected in Texas because owning a television does not mean surrendering your personal information to Big Tech or foreign adversaries." Spokespersons for Sony, Samsung, Hisense, and TCL were not immediately available for comment when contacted by BleepingComputer earlier today. An LG spokesperson told BleepingComputer that, "As a matter of policy, LG Electronics USA does not generally comment on pending legal matters such as this." Almost a decade ago, in February 2017, Walmart-owned smart TV manufacturer Vizio paid $2.2 million to settle charges brought by the U.S. Federal Trade Commission and the New Jersey Attorney General that it collected viewing data from 11 million consumers without their knowledge or consent using a "Smart Interactivity feature. The two agencies said that since February 2014, Vizio and an affiliated company being watched, including content from cable, streaming services, and DVDs. According to the complaint, Vizio also attached demographic information (such as sex, age, income, and education) to the collected data and sold it to third parties for targeted advertising purposes. In August 2022, the FTC published a consumer alert on securing Internet-connected devices, advising Americans to adjust the tracking settings on their smart TVs to protect their privacy. Update December 16, 12:43 EST: Added LG statement. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comDec 16, 2025extracted
Texas sues 5 smart TV manufacturers over data collection practices
Texas sues 5 smart TV manufacturers over data collection practices Texas is suing five major television manufacturers for using technology that records what consumers watch and for allegedly deceiving customers about the practice. Attorney General Ken Paxton on Monday filed suits against Sony, Samsung, LG, Hisense and TCL Technology Group Corporation for using what is known as automated content recognition (ACR) technology to capture individuals’ viewing habits in real time. Paxton, who is suing under the Texas Deceptive Trade Practices Act, says the well-known technology violates Texas law because of how it collects consumer data without the user’s knowledge or consent. ACR is used to recommend content to viewers, but can also be a tool to serve personalized ads or collect and sell user data in bulk. “When families buy a television, they don’t expect it to spy on them,” the lawsuits say. “They don’t expect their viewing habits [to be] packaged and auctioned to advertisers.” The five companies “deceptively” direct consumers to turn ACR on and bury “any explanation of what that means in dense legal jargon that few will read or understand,” the lawsuits say, calling disclosures “hidden, vague, and misleading.” Nearly three-quarters of U.S. households are equipped with a smart TV using ACR, the lawsuits say. ACR has been a target of lawmakers in the past. In 2017, the FTC and the New Jersey Attorney General fined Vizio $2.2 million for using ACR to capture data on 11 million consumers without their knowledge or consent. By 2021, the lawsuits say, Vizio reported that more of its profits stemmed from selling consumer data collected through ACR to advertisers than from selling TVs. ACR can collect data on things like watched YouTube videos, security or doorbell camera streams, and video or photos sent via Apple AirPlay or Google Cast, the lawsuits say. It can collect data from devices like personal laptops that are connected to TVs by HDMI. ACR can capture data even when a TV is offline, and can be sent to the company when the TV is reconnected to the internet, including for firmware updates, the lawsuits say. ACR data also is combined with metadata and identifiers, the lawsuits say, so that ACR can infer “highly personal attributes pertaining to consumers’ race, sex, or religious and political beliefs, all of which fall under sensitive personal data categories under Texas’ state privacy law and nearly every other privacy regime both nationally and internationally.” Hisense and TCL’s ties to China are especially disturbing, Paxton said in a press release, citing the potential for data harvesting by the Chinese government. Spokespersons for Hisense and LG said their companies do not comment on pending legal matters. None of the other TV manufacturers immediately responded to a request for comment. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaDec 15, 2025extracted
Attacco cyber contro Coupang, pubblicati i dati di oltre 33milioni di clienti
L’azienda Coupang, che vende dispositivi elettronici online, ha subìto un attacco hacker su vasta scala, con il furto dei dati di oltre 33milioni di suoi clienti. Indaga la Polizia della Corea del Sud. Coupang, la piattaforma di e-commerce più popolare in Corea del Sud, ha subìto un attacco cyber su vasta scala. Pubblicati i dati personali di oltre 33milioni di clienti. Dalle indagini della Polizia è emerso che la violazione dei server sarebbe cominciata lo scorso 24 giugno. Tuttavia, ha riportato la Reuters, “l’azienda non è venuta a conoscenza del problema fino al 18 novembre“. I principali sospetti, secondo l’emittente JTBC, sarebbero andati – dopo una serie di indagini interne – su un ex dipendente cinese, responsabile delle attività di autenticazione. Intanto, più di 10mila potrebbero intentare un’azione legale collettiva contro Coupang. L’avvocato Ha Hee-bong ha spiegato che si potrebbe arrivare fino ad un risarcimento di oltre 100.000 won (68 dollari) a persona. Fondata nel 2010 dal coreano-americano Bom Kim, Coupang ha in pochi anni guadagnato grandi quote di mercato. Tanto che, ad oggi, si sta espandendo anche in altri settori, quali la consegna di cibo a domicilio, lo streaming e la fintech. Anche per questo nei suoi server si trova una vasta mole di dati. Il monito delle autorità sudcoreane Kang Hoon-sik, capo di gabinetto del presidente sudcoreano, lunedì scorso ha affermato che i quattro principali incidenti cyber dal 2021 hanno evidenziato “lacune strutturali”. In particolare “nella protezione dei dati personali in Corea del Sud“. Negli ultimi mesi, la Corea del Sud è stata spesso al centro delle cronache per attacchi interni di hacker criminali. La violazione dei server di Coupang, di fatto, è avvenuta contemporaneamente a quella contro LG Uplus. Ad agosto, poi, il più grande operatore di telefonia mobile del Paese, SK Telecom, aveva ricevuto una multa di134 miliardi di won (96,53 milioni di dollari) dopo un attacco informatico. In quel caso, c’era stata una fuga di dati di quasi 27milioni di utenti. Quali i settori più colpiti? Più in generale, gli analisti hanno segnalato come tutte queste operazioni abbiano interessato i comparti nevralgici del ‘Sistema Paese’ sudcoreano. Ossia: le telecomunicazioni. Le società di carte di credito. Le startup tecnologiche. Varie agenzie governative. Mentre Seoul continua ad accusare la Cina e la Corea del Nord, diversi esperti hanno segnalato come i problemi restino fondamentalmente due. Il primo luogo, un sistema di sicurezza informatica che è frammentato e non centralizzato. Si è registrata inoltre la carenza di tecnici. Da qui, la moltiplicazione delle opportunità per i cyber criminali, con risposte spesso poco tempestive. Per questo, lo stesso Kang ha affermato che l’incidente cyber contro Coupang, “dovrebbe essere un’opportunità per migliorare il sistema di risarcimento punitivo“. Nell’occasione, infatti, questo “la sua applicazione non sarebbe avvenuta in modo tale da impedire una compromissione massiccia dei dati“.
cybersecitalia.itDec 2, 2025extracted
Loading 9 more…